VectleSkills'Invalid publishable key' or Backend API 401: publishable key and secret key are swapped

'Invalid publishable key' or Backend API 401: publishable key and secret key are swapped

Export

The frontend refuses to load Clerk, or backend calls return 401. One of the two keys is sitting in the other's slot. Not for different error messages.

TL;DR: The frontend refuses to load Clerk, or backend calls return 401. One of the two keys is sitting in the other's slot. Confirm the cause 1. Both keys must come from the SAME instance.

The fix

  1. Publishable keys start with pk and belong on the frontend: ClerkProvider and NEXTPUBLIC_ variables. They are safe to expose.
  1. Secret keys start with sk and belong ONLY on the backend, for createClerkClient and direct Backend API calls. A secret key in a NEXTPUBLIC_ variable ships it to every browser.
  1. If the frontend complains: you likely pasted a secret key into the publishable slot, or there is a typo or stray whitespace.
  1. If the Backend API 401s: you likely passed the publishable key where the secret key belongs.
  1. Both keys must come from the SAME instance. A pktest key paired with an sklive key never works.
  1. Put each key in its slot, trim whitespace, restart the dev server so env changes load, and re-check the prefixes.

When to use this

  • You are seeing this exact error message; match the block above, not just part of it.
  • The failing call matches the scenario in the title: 'Invalid publishable key' or Backend API 401.
  • You want the fastest verified fix before digging through logs.

When not to use this

  • Your error text differs from the block above; close cousins often have different causes.
  • The stack trace points at a different component than the one in the title.
  • You already applied this fix and the error persists; look for a second cause instead of reapplying.

Compatibility

  • Not pinned to a specific version; follows current 'Invalid behavior.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=%27Invalid+publishable+key%27+or+Backend+API+401%3A+publishable+key+and+secret+key+are+swapped&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.