API Documentation
- API Keys Overview & Getting Started
- Creating & Managing API Keys
- Authentication & Scopes
- Read-Only Endpoints Reference
- Error Handling & Troubleshooting
- Best Practices & Security
- Python Integration Examples
- JavaScript Integration Examples
- Bulk Import API, AIRTA & Imported Reports
- AILP - LLM compliance SDK (@airtasystems/ailp)
Creating & Managing API Keys
Jan 15, 2025
Creating an API Key
API keys can only be created through the web interface at API Key Management by company owners or admins.
Step-by-Step Process
- Navigate to API Key Management in your dashboard
- Click Generate API Key
- Configure your key:
Configuration Options
Name
Provide a descriptive name for your key (e.g., "Production Dashboard Integration", "GRC Platform Sync"). This helps you identify the key's purpose later.
Scopes
Select read permissions based on what data you need to access:
read:programs- Read program information and team access listsread:submissions- Read submission/report data with team attributionread:users- Read user informationread:teams- Read team information, members, and performance metricsread:reports- Read compliance reports (FRIA, incidents, compliance documents)
Best Practice: Only grant the minimum scopes needed for your use case.
IP Restrictions (Optional)
Whitelist specific IP addresses for enhanced security. This ensures the key can only be used from approved locations.
- Enter one IP address per line
- Supports both IPv4 and IPv6
- Leave empty to allow from any IP
Expiration (Optional)
Set an expiration date for additional security. The key will automatically become invalid after this date.
- Use for temporary integrations
- Helps enforce key rotation
- Leave empty for no expiration
⚠️ Important: Save Your Key Immediately
After creating an API key, save it immediately - it's only shown once! If you lose it, you'll need to create a new key.
Managing Existing Keys
Viewing Keys
- Go to API Key Management
- See all your active keys with their names, scopes, and last used timestamps
- Note: The actual key value is never shown again for security
Revoking Keys
- Click Revoke next to any key to immediately invalidate it
- Use this if a key is compromised or no longer needed
- Revoked keys cannot be restored
Monitoring Usage
- Check
lastUsedAttimestamp to see when keys were last used - Monitor for unexpected usage patterns
- Regularly review and rotate unused keys
Best Practices
- Use descriptive names - Makes it easy to identify key purposes
- Minimal scopes - Only grant permissions you actually need
- IP restrictions - Limit keys to specific IPs when possible
- Set expiration dates - Especially for temporary integrations
- Rotate regularly - Create new keys periodically and revoke old ones
- Monitor usage - Check lastUsedAt timestamps regularly