API Documentation
- API Keys Overview & Getting Started
- Creating & Managing API Keys
- Authentication & Scopes
- Read-Only Endpoints Reference
- Error Handling & Troubleshooting
- Best Practices & Security
- Python Integration Examples
- JavaScript Integration Examples
- Bulk Import API, AIRTA & Imported Reports
- AILP - LLM compliance SDK (@airtasystems/ailp)
Best Practices & Security
Jan 15, 2025
Security Best Practices
1. Store Keys Securely
Never commit API keys to version control.
- ❌ Don't: Commit keys to Git repositories
- ❌ Don't: Hardcode keys in source code
- ❌ Don't: Share keys in chat or email
- ✅ Do: Use environment variables
- ✅ Do: Use secret managers (AWS Secrets Manager, HashiCorp Vault, etc.)
- ✅ Do: Store keys in secure configuration files outside version control
2. Use Environment Variables
Store API keys in environment variables:
# .env file (add to .gitignore)
airtasystems_API_KEY=gb_live_your_api_key_here
# Load in your application
import os
api_key = os.getenv('airtasystems_API_KEY')
3. Rotate Keys Regularly
- Create new keys periodically (e.g., every 90 days)
- Revoke old keys after confirming new keys work
- Update integrations to use new keys
- Monitor for any issues during rotation
4. Use IP Restrictions
Limit keys to specific IP addresses when possible:
- Whitelist only the IPs that need access
- Use static IPs for server integrations
- Consider VPN or proxy for dynamic IPs
- Regularly review and update IP whitelists
5. Set Expiration Dates
Use expiration dates for additional security:
- Set expiration for temporary integrations
- Use shorter expirations for higher-risk scenarios
- Plan key rotation before expiration
- Monitor expiration dates and renew as needed
6. Minimal Scopes
Only grant the minimum scopes needed:
- Review what each scope allows
- Grant only necessary permissions
- Use separate keys for different integrations
- Regularly audit and remove unused scopes
7. Monitor Usage
Regularly check key usage:
- Review
lastUsedAttimestamps in API Key Management - Monitor for unexpected usage patterns
- Set up alerts for unusual activity
- Revoke keys that show suspicious activity
Integration Best Practices
Error Handling
Implement robust error handling:
try:
response = requests.get(url, headers=headers)
response.raise_for_status()
data = response.json()
except requests.exceptions.HTTPError as e:
if e.response.status_code == 401:
# Handle invalid API key
logger.error("Invalid API key")
elif e.response.status_code == 403:
# Handle insufficient scopes or IP restriction
logger.error("Access denied")
else:
# Handle other errors
logger.error(f"API error: {e}")
Rate Limiting
Implement rate limit handling:
- Check
X-RateLimit-Remainingheader - Implement exponential backoff
- Respect rate limit windows
- Cache responses when appropriate
Retry Logic
Implement retry logic for transient failures:
import time
def make_request_with_retry(url, headers, max_retries=3):
for attempt in range(max_retries):
try:
response = requests.get(url, headers=headers)
response.raise_for_status()
return response.json()
except requests.exceptions.RequestException as e:
if attempt < max_retries - 1:
wait_time = 2 ** attempt # Exponential backoff
time.sleep(wait_time)
else:
raise
Key Management Workflow
Creating Keys
- Go to API Key Management
- Click Generate API Key
- Configure name, scopes, IP restrictions, expiration
- Save the key immediately (shown only once)
- Store securely in environment variable or secret manager
Rotating Keys
- Create a new key with same scopes and restrictions
- Test the new key in a non-production environment
- Update your integration to use the new key
- Verify everything works with the new key
- Revoke the old key
Revoking Keys
- Identify the key to revoke
- Verify it's no longer needed
- Click Revoke in API Key Management
- Confirm revocation
- Update any documentation referencing the key
Security Checklist
- ✅ API keys stored in environment variables or secret managers
- ✅ Keys never committed to version control
- ✅
.envfiles added to.gitignore - ✅ IP restrictions configured where possible
- ✅ Expiration dates set for temporary integrations
- ✅ Minimal scopes granted
- ✅ Keys rotated regularly
- ✅ Usage monitored regularly
- ✅ Error handling implemented
- ✅ Rate limiting respected
What to Do If a Key Is Compromised
- Immediately revoke the key in API Key Management
- Review recent API usage for suspicious activity
- Create a new key with appropriate scopes
- Update all integrations to use the new key
- Review and tighten security practices
- Consider enabling additional IP restrictions
- Monitor for any unauthorized access