Docs/Start/Authentication

Authentication

One key for your whole account. Where it lives, how to connect it, what a rejection looks like, and how to rotate without downtime.

View as Markdown

You connect once, in the sidebar, and every formula in every workbook uses that connection. No key goes in a cell, in a formula, or in the file.

=VERVE("dadjokes", "field", "joke")

Your key is on the API keys page of the dashboard. A new account has one the moment it exists — there is no provisioning step.

Connecting

Open the sidebar — Extensions → VerveSheets → Open VerveSheets in Google Sheets, or the VerveSheets button on the Home ribbon in Excel — and pick one of two paths:

What it doesWhen to use it
Sign inRuns the consent screen and stores a token that renews itselfThe default. Nothing to copy or keep track of.
Paste a keyStores the key you copied from the dashboardWhere an organisation policy blocks the consent screen.

Either way the credential is stored by the add-in against your account, not inside the workbook. It is not in the file, not in version history, and not in a shared link.

What a collaborator sees

Share a workbook and the formulas keep working — the calls bill the owner's credits, because the owner's credential is the one running them. A collaborator who wants their own billing installs the add-in and connects on their own account.

The status dot at the top of the sidebar is the whole answer to "is this connected". Disconnect at the foot of the panel clears the stored credential; formulas stay in the sheet and stop resolving until you connect again.

What a key is

A key is a UUID: a1b2c3d4-e5f6-7890-abcd-ef1234567890.

One key covers your whole account: everything your plan includes, with no per-source enablement. What the key controls is:

  • Which plan applies — credits, rate limit and concurrency all come from the key's account.
  • What it may reach — optionally narrowed with key scoping.
  • Where it may be used from — optionally narrowed with an IP allow-list.
  • How long it lives — optionally given an expiry, see key expiration.

Additional keys, each with their own name and restrictions, are sub-keys.

What a disconnected cell looks like

There is no status code to read, so the cell says it in words:

Cell readsWhat happened
#ERR Connect first: Extensions ▸ VerveSheetsNo credential stored yet, or it was disconnected. Excel words it #ERR Not connected — connect in the VerveSheets pane.
#ERR UnauthorizedThe stored key is no longer recognised — usually rotated or revoked elsewhere.
#PREMIUM(fieldName)The credential is fine; the plan does not include that field.

The first one is worth knowing by sight: a formula copied out of the sidebar's preview while signed out looks completely correct and returns that error. The preview carries a warning underneath for exactly this reason.

Keeping the key safe

The add-in already does most of this — the credential is not in the file, so it does not travel with a copy or a share link. Three things still worth doing:

  • Prefer signing in over pasting a key. The token renews itself and there is no copy of a key on your clipboard, in an email, or in a chat.
  • Never type a key into a cell. Nothing asks you to, and a cell is the one place a credential would end up in the file, in version history, and in every export.
  • Use a sub-key for a shared workbook's owner account, so the workbook's spending is separable from everything else on the account.

Rotating a key

Rotation replaces the key with a new one and invalidates the old one immediately. There is no grace period, so the order matters:

  1. Create a sub-key for the workload, or note where the current key is in use.
  2. Roll the new key out everywhere first.
  3. Rotate only once nothing is still reading the old value.

If you connected by signing in, rotation does not disturb you — reconnect only if the sidebar starts reporting an error. If you pasted a key, rotating it means pasting the new one into the sidebar on every device you use.

If a key has leaked, invert that: rotate first and accept the downtime. A leaked key is spending your credits for as long as it works.

Full procedure, including the zero-downtime pattern with overlapping sub-keys, is in key rotation.

Checking a key works

The status dot at the top of the sidebar. Connected means formulas will resolve; the credit meter beside it means the account behind them is reachable and answering.

If the dot says connected but cells still fail, the credential is fine and the problem is in the formula — see formulas for what each #ERR message means.

Next

With the add-in connected, formulas is the full function reference and the sidebar covers doing it without typing.

If your key needs to be narrower than your account, start at key scoping. The key itself lives on the dashboard, alongside the usage it spends.

Was this page helpful?

Last updated