Authentication
Live Hive issues two project keys. They are not interchangeable.
iOS Public Key
Authorization: Bearer lh_pub_...Safe to include in your iOS app. It can only call POST /v1/activities/register. It cannot update, end, or read activities, and it cannot access APNs configuration.
Server API Key
Authorization: Bearer lh_live_...Keep this secret. Never put it in your iOS app. There is no server SDK. The dashboard can send a test update without this key leaving the server. POST update and end from your backend over HTTP when you have one, any language. Keys are hashed at rest. Live Hive shows the full secret key only when it is created. If you lose it, revoke it and create another.
Where to get a key
Open the project. Create an iOS public key for the app and a server API key for your backend. Each key is scoped to that project. A public key cannot register into a different project.
Treat public keys as extractable
An iOS public key can be pulled out of the app binary. That is expected. It still cannot update, end, or read activities. It can only register tokens for its own project. Prefer unguessable activity IDs so a leaked public key cannot overwrite another device’s token by guessingactivity_id. Revoke and rotate the public key if it is abused.
Base URL
Canonical host: https://www.livehive.dev/v1. Use that in new code. https://www.livehive.dev/api/v1 is the same API.