# Dashboard

> Find your keys, and see what a /validate response can include.

Source: https://docs.centinelanalytica.com/install/dashboard

## What you'll do here

1. Find and copy your integration keys (site key + secret key). Centinel normally generates both when it creates your organisation; check the Organisation page and regenerate either key if it is missing.

2. Review your policy rules. Add and order path-specific rules where you need different behavior. See [Policy Rules](https://docs.centinelanalytica.com/admin/policy.md).

> **Warning:** Keys authenticate `/validate`; they do not enforce traffic. Before relying on blocks, add and
> verify a matching policy rule. Then have your backend or platform integration act on the
> `/validate` response.

The dashboard opens on **Insights**. **Analytics** has an endpoint tree showing which paths
actually receive traffic, which is the quickest way to decide what to protect first. **Crawlers**
holds the allowlist. Source-IP verification and allowlist membership determine `access_allowed`.
**Threats** shows what Centinel blocked and why. Press `⌘``K` (or
`Ctrl``K`) to jump to any of them.

## API keys

Centinel issues two kinds of key, on two different pages under **Organisation**.

### Integration keys

On the [Organisation](https://dash.centinelanalytica.com/organisation) page, under **Integration
keys**:

* **Site key (public)**: used in the browser script URL. Safe to expose.
* **Secret key (sensitive)**: used as `x-api-key` when your backend calls `/validate`. Keep this server-side only—store it in environment variables or a secret manager.

> **Never expose the secret key:** The `x-api-key` is server-only. Don't put it in client-side code, HTML, or public repositories.

### Analytics keys

The **API keys** page at
[Organisation → API keys](https://dash.centinelanalytica.com/organisation/tokens) issues the
`sk_api_ro_` keys that the [Analytics Query API](https://docs.centinelanalytica.com/api/analytics.md) and the
[MCP server](https://docs.centinelanalytica.com/api/mcp.md) accept as a bearer token. These are separate from your integration keys
and cannot call `/validate`. Create one key per integration so you can revoke it on its own.

## Crawler metadata

`/validate` responses can carry a `crawler` object identifying which crawler made the request. It
holds `id`, `name`, and `access_allowed`, plus `category` and `rsl_category` when the catalog entry
resolves. See [Crawlers](https://docs.centinelanalytica.com/api/crawlers.md) for the full schema.

`/validate` includes this object only when the `validate_response_include_crawler` feature flag is
enabled for your organisation. Crawler detection is always active, and you manage the allowlist on
the **Crawlers** page either way.

Once you have both integration keys, continue to:

* [Add scripts](https://docs.centinelanalytica.com/install/scripts.md): Install the browser script using your site key, and make sure it loads wherever protected actions can be triggered.
* [Validate requests](https://docs.centinelanalytica.com/install/validation.md): Call /validate from your backend using your secret key, then enforce the returned decision.
