{"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"manage-api-keys","__idx":0},"children":["Manage API keys"]},{"$$mdtype":"Tag","name":"ConfigOptionRequirements","attributes":{"products":["Redoc","Revel","Reef","Realm"],"plans":["Pro","Enterprise","Enterprise+"]},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["An API key is a unique identifier used to authenticate a user, developer, or an application to an API."," ","You can add API keys to your organization and revoke them when you are finished using them."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If you don't set an expiration date when you create a key, the key does not automatically expire and stays valid until manually revoked."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Redocly stores API keys as one-way cryptographic hashes in the backend."," ","The plaintext value of the key can't be retrieved."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"add-api-keys","__idx":1},"children":["Add API keys"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can add API keys to your organization if you need to access the Redocly API or the Scout tool."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To add an API key:"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Log in to your Redocly instance."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Access"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API keys"]}," in the navigation menu on the left side of the page."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New key"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Enter a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name"]}," for your key."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Choose a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Permission model"]}," for the key and set the permissions it grants."," ","For details on each model and the available permissions, see ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#api-key-permissions"},"children":["API key permissions"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["(Optional) Set an ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Expiration date"]},"."," ","After this date (UTC), the key stops working."," ","Leave it empty to create a key that stays valid until you revoke it."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["(Optional) Restrict the key to one or more allowed IP addresses."," ","This option is available on plans that include IP restrictions."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Create"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click the copy icon next to the newly created API key to save it to your clipboard."," ","Save the key somewhere safe, as you can't access it again later."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"api-key-permissions","__idx":2},"children":["API key permissions"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Every API key has a ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["permission model"]}," that determines what the key is allowed to do."," ","You select the permission model when you create a key, and you can change it later by editing the key."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The API keys list shows the permission model for each key in the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Permission model"]}," column."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"permission-models","__idx":3},"children":["Permission models"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Permission model"},"children":["Permission model"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Granular permissions"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Grant the key a specific set of organization and project permissions that you select individually."," ","Use this model when you want to scope a key to only the operations it needs."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["RBAC"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Assign the key to one or more ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/teams"},"children":["teams"]},"."," ","The key inherits the roles and permissions of those teams, following the same ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/access/rbac"},"children":["role-based access control"]}," logic that applies to users."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Legacy full access"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["A read-only model shown for older keys that were created with unrestricted access."," ","You can't create new keys with this model."," ","To save changes to a legacy key, convert it to ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Granular permissions"]}," or ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["RBAC"]},"."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"granular-permissions","__idx":4},"children":["Granular permissions"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When you select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Granular permissions"]}," model, you choose from a list of organization permissions and a list of project permissions."," ","You must select at least one permission."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Each permission has a type that describes the kind of access it grants:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Read"]}," permissions allow viewing or listing resources."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Write"]}," permissions allow creating or updating resources."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Delete"]}," permissions allow removing resources."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Use the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Quick select"]}," buttons above each list to set permissions in bulk:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Full access"]}," selects every permission in the list."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Read only"]}," selects only the read-type permissions in the list."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["None"]}," clears the selection."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"organization-permissions","__idx":5},"children":["Organization permissions"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Permission"},"children":["Permission"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Grants"},"children":["Grants"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["org.organizations.read"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["View organization details and settings."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["org.organizations.update"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Write"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Update organization details and settings."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["org.project.read"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["List and view projects in the organization."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":4,"id":"project-permissions","__idx":6},"children":["Project permissions"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Permission"},"children":["Permission"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Grants"},"children":["Grants"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["project.git.branch.delete"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Delete"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Delete branches in a project."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["project.git.branches.read"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["List and view branches in a project."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["project.remotes.create"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Write"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Create project remotes."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["project.remotes.delete"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Delete"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Delete project remotes."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["project.remotes.read"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Read"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["List and view project remotes."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["project.remotes.update"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Write"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Update project remotes."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"rbac-permission-model","__idx":7},"children":["RBAC permission model"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When you select the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["RBAC"]}," model, you assign the key to one or more ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/teams"},"children":["teams"]}," instead of selecting individual permissions."," ","The key is granted the same access as a member of those teams, following the roles assigned to them."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The access logic follows the same principles as standard ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/access/rbac"},"children":["RBAC configuration"]},"."," ","API keys assigned to a team have access to the resources that the team's roles allow."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"revoke-api-keys","__idx":8},"children":["Revoke API keys"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["When you are finished using an API key, you can revoke the key, making it an invalid authentication method."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Log in to your Redocly instance."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Access"]}," > ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["API keys"]}," in the navigation menu on the left side of the page."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["More options"]}," next to the API key you want to revoke, then click ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Revoke"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm that you want to revoke the key."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"resources","__idx":9},"children":["Resources"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/manage-orgs"},"children":["Manage your organization"]}]}," - Set up the details and manage your Redocly organization"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/access/rbac"},"children":["Role-based access control"]}]}," - Control authorization based on roles and team membership"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/access/roles"},"children":["Roles and permissions"]}]}," - Explore the user roles and permissions available for controlling access to your organization and projects"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/sso"},"children":["Single sign-on (SSO) configuration"]}]}," - Complete SSO configuration reference with examples for various identity providers"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/teams"},"children":["Manage teams"]}]}," - Organize users into teams with role-based permissions for effective collaboration and access control"]}]}]},"frontmatter":{"products":["Redoc","Revel","Reef","Realm"],"plans":["Pro","Enterprise","Enterprise+"]},"tagList":["configOptionRequirements","table"],"title":"Manage API keys","lastModified":"2026-10-01T23:00:57.000Z"}