Skip to main content

API Keys

Purpose: Manage machine credentials for integrations, automation, and programmatic access.

Create a Key​

  • Provide a descriptive name and owner.
  • Select scopes that limit the key’s permissions (read-only vs. write).
  • Optionally set an expiration (recommended for short-lived keys).

Revoke a Key​

  • Immediate action to block access from compromised or retired credentials.


Security & Best Practices​

  • Use narrow scopes and shortest practical lifetimes.
  • Store secrets in secret management systems (vaults) and not in code or email.
  • Audit and remove keys that are unused beyond a threshold (e.g., 90 days) via Audit Log.

Troubleshooting​

  • API requests returning unauthorized:
    • Confirm key is active, not expired, and the scope covers the requested operation.
    • Check for clock drift in signed token-based implementations.

Operational Checklist​

  • Enforce rotation schedule and require owners to validate downstream updates before revoking old keys.