> ## Documentation Index
> Fetch the complete documentation index at: https://docs.proofage.net/llms.txt
> Use this file to discover all available pages before exploring further.

# Workspaces and keys

> Create test and live workspaces, choose the check, and manage and rotate secret keys.

Everything about a workspace is on its page under **Workspaces** in the [console](https://app.proofage.net). What a workspace is, and why you need a test and a live one, is on [Concepts](/getting-started/concepts#workspace).

## Create a workspace

**Create Workspace** asks:

* **What should this workspace check?**
  * **Identity (KYC)**: the person scans their ID and takes a selfie. API: `flow_type: kyc`.
  * **Age verification → ID document** (*Highest assurance*): the same capture as Identity, plus your minimum age, from 16 to 25. API: `flow_type: age`, `age_mode: document_verification`.
  * **Age verification → Facial age estimation** (*Fast & easy*): a selfie, 18+ only. When the selfie can't confirm 18+, the person adds an ID in the same session; nobody is declined on the selfie alone. API: `flow_type: age`, `age_mode: estimation`.
* **Mode**: **Live** (the default) or **Test**. A test workspace runs the real widget, but nothing is analysed or billed and you choose each outcome yourself. The mode cannot be changed later.
* **A name** your team recognises.

Identity versus age verification is fixed once the workspace exists. An age workspace can later switch between its two methods and change its minimum age. On the workspace's page these appear as **Verification**, **Method** and **Minimum age**.

Administrators and developers can create and change workspaces; support specialists can see them.

## Settings

| Setting | What it does |
| - | - |
| **Webhook URL** | Where [decision webhooks](/integration/webhooks) are sent. Empty means no webhooks. A public `https` URL: private and local addresses are refused; see [the webhook URL](/integration/webhooks#the-webhook-url). |
| **Redirect URL** | Where the person's browser goes after the final screen, when the verification has no `callback_url`. An `http` or `https` URL. A new workspace points at a ProofAge page. |
| **Allow expired documents** | Accept identity documents past their expiry date. Off by default. |
| **Allow duplicate accounts** | Let one face verify under several of your user IDs. On by default; turn it off to run [duplicate detection](/core-technology/duplicate-detection). |
| **External profile URL template** | A link to the person in your own admin, with `{{external_id}}` in it. The console shows it on each verification so your team can jump to the user. |

The page also shows ready-to-paste **integration code** for the [Browser SDK](/integration/web/browser-sdk), in a modal or a new tab, with the workspace's public key filled in.

A workspace can be **suspended**: its API answers `403 WORKSPACE_SUSPENDED` and its open links stop working, until you reactivate it.

## Keys

| | |
| - | - |
| **Public key** | `pk_test_…` or `pk_live_…`. Identifies the workspace; safe in a browser. |
| **Secret keys** | `sk_test_…` or `sk_live_…`. Sign API requests. A workspace holds up to **five**. Any of them signs requests; exactly one is **active**, and only the active key signs the webhooks ProofAge sends you. |

Store secret keys in environment variables or a secrets manager, never in source control or client-side code. How they are used is on [API authentication](/getting-started/api-authentication).

### Rotate a secret key without downtime

<Steps>
  <Step title="Create a new key">
    Add a secret key on the workspace's page. The old one keeps working.
  </Step>

  <Step title="Deploy it">
    Sign API requests with the new key. In your webhook handler, accept a signature made with either key for now.
  </Step>

  <Step title="Make it active">
    Set the new key as active. From now on webhooks are signed with it.
  </Step>

  <Step title="Delete the old key">
    Once nothing uses it, delete it: requests signed with it are refused from then on. Remove it from your webhook handler too.
  </Step>
</Steps>

If you reach five keys, delete an unused one before creating another. The active key cannot be deleted; make another one active first.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.