# API Keys

Before you can make API calls, you need a Checkr account. Checkr provides a **staging environment** for development and a **production environment** for live checks.

## Create an account

Staging
**Sign up**

Go to [partners.checkrhq-staging.net](https://partners.checkrhq-staging.net/authorize/996cac96ae5280bf77c44025/welcome) and create a free developer account. You'll be asked for basic company information.

**Verify your email**

After signing up, check your inbox for a verification email from Checkr. Click the link to activate your account.

**Access the staging environment**

Log in to [dashboard.checkrhq-staging.net](https://dashboard.checkrhq-staging.net) with your newly created credentials.

Staging uses fake data — no real background checks are run and no real PII is processed. Always use staging for development and testing. Your staging account is separate from your production account and uses its own API keys.

**Staging limitations.** Staging is for building and testing, so some production features are intentionally unavailable:

- **No adverse action** — the adverse action flow does not run in staging.
- **No invoices** — staging does not generate invoices or bill for usage.
- **No analytics** — analytics and reporting are not populated in staging.
- **Invitations don't expire** — staging invitations stay valid indefinitely, unlike production.


Production
**Sign up**

Go to [dashboard.checkr.com](https://dashboard.checkr.com) and create an account. You'll be asked for basic company information including business verification.

**Verify your email**

After signing up, check your inbox for a verification email from Checkr. Click the link to activate your account.

**Request production access**

A production account requires credentialing. Checkr reviews your use case, integration approach, and compliance posture before granting production access.

To request production access, contact Checkr through your dashboard or reach out to your account representative.

## Get your API keys

Checkr uses separate API keys for staging and production. You'll need a staging key to develop and test, and a production key when you're ready to go live.

Start with staging. Staging keys cannot trigger real background checks or access production data, making them safe for development.

Staging
Use staging to build and test your integration before going live.

**Log in to your staging account**

Log in to [dashboard.checkrhq-staging.net](https://dashboard.checkrhq-staging.net/)

**Navigate to Developer Settings**

Go to **Account Settings → Developer Settings**.

**Create a Secret key**

Click **Create Secret Key**. Give it a name (e.g. "Local dev") and copy it immediately — it will not be shown again.

**Store it securely**

Save the key in your local environment:

```bash
export CHECKR_API_KEY=your_staging_key_here
```

Staging and production are completely separate environments. Candidates, reports, and packages created in staging do not carry over to production.

Production
Production access requires completing the Checkr account setup process and, for partners, passing an integration review.

**Complete your Checkr account setup**

Log in to [dashboard.checkr.com](https://dashboard.checkr.com) and complete onboarding, including business verification.

**Navigate to Developer Settings**

Go to **Account Settings → Developer Settings**.

**Create a Secret key**

Click **Create Secret Key**. Name it clearly (e.g. "Production server") and copy it immediately.

**Store it securely**

Use a secrets manager (AWS Secrets Manager, HashiCorp Vault, etc.) or environment variables. Never commit production keys to source control.

**Partners:** Production access also requires completing an [integration review](/partners/production-approval) with a Checkr Partner Manager before your keys are activated for live checks.

## Key types

Checkr issues two types of API keys per environment:

| Key Type | Use |
|  --- | --- |
| **Secret key** | Server-side only. Full API access. Never expose in client-side code. |
| **Publishable key** | Client-side use with Checkr's JS SDK only. Safe to expose in frontend code. |


For most API integrations you only need the Secret key.

## Authenticate your requests

The Checkr API uses **HTTP Basic Auth**. Pass your API key as the username with a blank password.

Staging
**Base URL:** `https://api.checkr-staging.com/v1`

```bash
curl -u $CHECKR_API_KEY: https://api.checkr-staging.com/v1/candidates
```

Production
**Base URL:** `https://api.checkr.com/v1`

```bash
curl -u $CHECKR_API_KEY: https://api.checkr.com/v1/candidates
```

The trailing colon (`:`) after the API key tells `curl` to send a blank password. This is the correct format for HTTP Basic Auth with Checkr.

## Security best practices

Never commit API keys to source control, log files, or error messages.

- **Use staging keys during development.** Staging keys cannot trigger real checks or access production data.
- **Rotate keys immediately if compromised** — generate a new one from the Dashboard and revoke the old one.
- Use separate keys for each environment and each service.
- Restrict access to production keys to only the team members who need them.