What the developer API is
The developer API is a small, programmatic surface your own code can call directly with a long-lived API key: a plugin, a CI job, an export script. A key is a bearer credential of the form rc_live_ followed by random characters. It resolves to exactly one tenant and carries a fixed set of scopes that bound what it may do, so a key can never read or write another tenant's data.
This is separate from the plugin request-signing protocol (used by the recorder) and from your signed-in panel session. Use a customer API key whenever you want to integrate from outside the recorder.
Minting a key
Mint, list, and revoke keys from the dashboard under Settings, then Developer API. Give the key a name, choose its scopes, and optionally set an expiry. The full plaintext key (rc_live_) is shown exactly once at creation: copy it then and store it as a secret, because it is never shown again. The panel only ever stores a hash plus a short non-secret prefix (such as rc_live_a1b2c3) so it can label the key without revealing it.
If you lose a key, revoke it and mint a new one. A tenant may hold at most 50 live (non-revoked) keys at a time.
Scopes
A key must be granted at least one scope, and each endpoint enforces exactly the one scope it needs, by exact match. Sixteen scopes are available when you mint a key. Alongside replay, portal and network-integration scopes, servers:read lists connected servers and servers:write creates, renames and removes server setups. setup:read inspects the wider workspace configuration surface; setup:write changes it and can only be granted by an active workspace owner. A management key is bound to the member who created it, and that member's current dashboard permissions are checked on every management request. Removing or demoting the member therefore removes or reduces the key's access too.
Two further scopes exist that you cannot grant yourself. staff:bypass is the only scope that can reveal held (embargoed) footage before its release time, and admin covers actions with no narrower scope of their own, such as deletion and redaction. Both are withheld from the key dialog on purpose and are provisioned by support when an integration genuinely needs one. A key that lacks the scope an endpoint requires is rejected with 403 INSUFFICIENT_SCOPE.
Using a key
Present the plaintext key as a bearer token on the programmatic endpoints, which live under the /v1/api/ prefix on api.replaycore.com. The bearer-auth path resolves the key to its tenant and scopes, rejects revoked or expired keys, enforces the route's required scope, and scopes every downstream query to the resolved tenant.
# Mint a key once in the panel (Settings, then Developer API) and copy the rc_live_ secret.
KEY="rc_live_xxxxxxxxxxxxxxxxxxxx"
# List the tenant's five most recent replays through the developer API.
curl https://api.replaycore.com/v1/api/replays?page_size=5 \
-H "Authorization: Bearer $KEY"Authentication errors
A missing or non-Bearer Authorization header returns 401 UNAUTHENTICATED. A bearer value that is not an rc_live_ key, or resolves to no live key (unknown, revoked, or expired), returns 401 INVALID_API_KEY; the three cases are deliberately indistinguishable to the caller. A live key that lacks the required scope returns 403 INSUFFICIENT_SCOPE.
Keys with an expiry in the past resolve as expired and are rejected at auth exactly like a revoked key. The developer-API endpoints share a per-tenant rate limit with the other tenant-data endpoints.
Prefer the Java SDK?
If you are building a Bukkit, Paper, or Velocity plugin in Java, you do not have to hand-roll HTTP and JSON against these endpoints. The official ReplayCore Java SDK is open source and wraps this same developer API for you. See the Java SDK article in this section.