Skip to main content
Replied uses an API key in the submit URL.

API key rules

  • Create one key per website or integration.
  • Rotate keys after staff or vendor changes.
  • Remove unused keys.
  • Use allowed domains when you want origin checks.

Origin checks

If a key has allowed domains, Replied accepts browser submissions only from those origins.
Include the protocol. Do not enter only example.com.

Avoid breaking

Preserve API key validation, rate limits, and origin checks when editing submit flows.