Set up your account and get your keys
This guide shows you how to create a PubNub account, create an app and a keyset, and get the publish and subscribe keys your app passes to a PubNub SDK. It also shows you how to enable the features your app calls.
A keyset is the set of publish, subscribe, and secret keys that identifies your application to the PubNub network, and every feature you enable comes from that same keyset. Every step happens in the Admin Portal.
If you already have an account and an app, skip to Create a keyset.
Create an account
Sign up, or log in with your username and password, Google single sign-on, or your own SSO provider.
Create an app
You need at least one app before you can create a keyset.
- Go to Apps & Keysets.
- Select Create app.
- Enter a name and select Create.
Create one app per project, then use separate keysets inside it for each environment such as development, QA, and production.
The Admin Portal Apps screen lists up to 100 apps. For an account with more than 100 apps, the list appears empty.
In that case, search by name in the Apps dropdown in the top navigation bar instead.
Create a keyset
Create a keyset for your app:
- Select your app to open its keysets list.
- Select Create keyset.
- Enter a name, choose Testing or Production, and click Next.
- Configure the keyset services and click Create.
Choose Production if the keyset will carry live traffic. Creating a Production keyset requires at least the Starter plan. Testing keysets are rate-limited and aren't suitable for live traffic. A free PubNub account covers up to 200 monthly active users (MAUs) or 1 million transactions at no cost, whichever limit you reach first.
To decide how many keysets to create and how to map them to your environments, refer to environment-aligned keys.
Get your keys
Selecting a keyset opens its overview page, which shows all three keys.
- Copy the publish key, which starts with
pub-c-. - Copy the subscribe key, which starts with
sub-c-. - Pass both to the SDK when you initialize PubNub, as shown in Quickstart.
Copy the secret key only if your own server will generate Access Manager tokens.
The secret key grants privileged access to your PubNub application. It must remain on a trusted server and must never be included in client applications.
Always use the keys from your own keyset. Never use keys from another account or from someone else's keyset, including any published in a code sample or public repository.
Enable the features your app calls
Features are keyset-level switches: flip once, all clients in that environment get it. While you are on the keyset overview page, turn on the ones your app needs:
- Presence if you need to know who is currently connected to a channel.
- Message Persistence if clients will fetch history or recover messages missed while offline.
- App Context if you want PubNub to store user, channel, and membership metadata.
- File Sharing if clients will send files on a channel.
- Access Manager if you need to restrict which clients reach which resources.
- Mobile Push Notifications if you need to reach disconnected devices. Add your APNs or FCM credentials here as well.
- Stream Controller if you will use channel groups or wildcard subscribe.
Select any feature name to see its parameters and change them.
Next steps
Once your account and keyset are ready, here's where to go next:
- Quickstart - initialize the SDK and publish your first message
- Available SDKs - choose the SDK for your platform
Related tasks
- Rotate the secret key - stage replacement keys with future expiry dates
- Store credentials for Functions - keep third-party API keys out of your Function source
- Forward keyset events to your systems - send Presence, App Context, Message Persistence, and push events to Kafka, SQS, S3, or a webhook
- Invite organization members - give your team access and assign roles
- Monitor usage and costs - track billable metrics, and set a billing alert on Starter and Pro plans