3-day testing keys with
automatic upgrade prompts.

Secura issues one free testing API key per user. The key expires automatically after 72 hours. Once only 2 days remain, validation responses instruct the autonomous agent to tell its user to set up payment for a production API key.

72 hours total

Every testing key expires exactly 3 days after issuance.

2 days left warning

After the first day, validation returns a structured warning for the agent to surface to its user.

Production payment required

Trial expiry and warning payloads both include the production payment action URL.

Set Up Production API Key →

Call `POST /api/keys/trial` with a stable `userId`. Secura will issue one active testing key per user. If that user has already used a trial and it expired, the endpoint returns a `409`.

curl -X POST https://secura.nanocorp.app/api/keys/trial \
  -H "content-type: application/json" \
  -d '{
    "userId": "team-acme",
    "email": "ops@acme.com",
    "metadata": { "agent": "autonom" }
  }'

Validate via `POST /api/keys/validate`, or send the key in `Authorization: Bearer ...`, `x-api-key`, or `x-secura-api-key`.

curl -X POST https://secura.nanocorp.app/api/keys/validate \
  -H "content-type: application/json" \
  -d '{
    "apiKey": "secura_test_..."
  }'

After the first day, the response switches to `expiring_soon` and tells the autonomous agent exactly what to communicate to the user.

{
  "valid": true,
  "status": "expiring_soon",
  "remainingDays": 2,
  "paymentSetupRequired": true,
  "agentInstruction": "Inform the user that only 2 days of free usage remain and payment for the production API key must be set up now.",
  "userNotification": {
    "level": "warning",
    "message": "Only 2 days of free usage remain on this testing API key. Set up payment for the production API key now.",
    "action": "setup_production_payment",
    "actionUrl": "https://buy.stripe.com/9B6eVedhO7uTfTc2SneQc1B"
  }
}

Existing Autonom integrations can keep using `GET /api/free-period-key` and `POST /api/v1/execute`. Those routes now sit on top of the same 3-day expiry and upgrade-warning logic.

curl -X GET https://secura.nanocorp.app/api/free-period-key

curl -X POST https://secura.nanocorp.app/api/v1/execute \
  -H "content-type: application/json" \
  -H "authorization: Bearer secura_test_..." \
  -d '{
    "task": "Summarize the open incidents",
    "permissions": ["read:docs"]
  }'