Creating & Managing API Keys

    Jan 15, 2025

    Creating an API Key

    API keys can only be created through the web interface at API Key Management by company owners or admins.

    Step-by-Step Process

    1. Navigate to API Key Management in your dashboard
    2. Click Generate API Key
    3. Configure your key:

    Configuration Options

    Name

    Provide a descriptive name for your key (e.g., "Production Dashboard Integration", "GRC Platform Sync"). This helps you identify the key's purpose later.

    Scopes

    Select read permissions based on what data you need to access:

    • read:programs - Read program information and team access lists
    • read:submissions - Read submission/report data with team attribution
    • read:users - Read user information
    • read:teams - Read team information, members, and performance metrics
    • read:reports - Read compliance reports (FRIA, incidents, compliance documents)

    Best Practice: Only grant the minimum scopes needed for your use case.

    IP Restrictions (Optional)

    Whitelist specific IP addresses for enhanced security. This ensures the key can only be used from approved locations.

    • Enter one IP address per line
    • Supports both IPv4 and IPv6
    • Leave empty to allow from any IP

    Expiration (Optional)

    Set an expiration date for additional security. The key will automatically become invalid after this date.

    • Use for temporary integrations
    • Helps enforce key rotation
    • Leave empty for no expiration

    ⚠️ Important: Save Your Key Immediately

    After creating an API key, save it immediately - it's only shown once! If you lose it, you'll need to create a new key.

    Managing Existing Keys

    Viewing Keys

    • Go to API Key Management
    • See all your active keys with their names, scopes, and last used timestamps
    • Note: The actual key value is never shown again for security

    Revoking Keys

    • Click Revoke next to any key to immediately invalidate it
    • Use this if a key is compromised or no longer needed
    • Revoked keys cannot be restored

    Monitoring Usage

    • Check lastUsedAt timestamp to see when keys were last used
    • Monitor for unexpected usage patterns
    • Regularly review and rotate unused keys

    Best Practices

    • Use descriptive names - Makes it easy to identify key purposes
    • Minimal scopes - Only grant permissions you actually need
    • IP restrictions - Limit keys to specific IPs when possible
    • Set expiration dates - Especially for temporary integrations
    • Rotate regularly - Create new keys periodically and revoke old ones
    • Monitor usage - Check lastUsedAt timestamps regularly
    Creating & Managing API Keys | AIRTA Systems Support