How do I create an API key?
Quick answer
Open the Developer page in the admin panel, create a key, give it a name and choose its scopes. The full token is shown once at creation; copy it into your system's secret store immediately. You can revoke a key at any time, which stops it working straight away.
Detailed answer
Keys are tied to your firm and carry only the permissions you choose.
Steps
- Open Developer in the admin panel.
- Choose to create a key.
- Name it after the system that will use it, such as "Checkout webhook".
- Select scopes.
- Copy the token when it is shown. It will not be shown again.
Storing the token
- Keep it in your server's environment variables or a secrets manager.
- Never put it in browser code, mobile apps or a public repository.
- The token in the dialog is masked from session recording tools.
Using it
Send the token in the request's authorisation header, as described in the authentication section of the docs.
Revoking
Revoke a key from the Developer page if it may have leaked or a system is retired. Create a new key for the replacement.
Good practice
- One key per system, so you can revoke one without affecting others.
- The minimum scopes each system needs.
- Rotate keys periodically.
PropExecutor team · Updated