API keys
An API key authenticates your system to Kontier. You pass it as a bearer token, and every request resolves to the organization the key belongs to, which is why no request carries an organization parameter.
Scopes are required
A key must say what it may do. name and scopes are both required, and
scopes must contain at least one permission.
There is no "full access" key. An empty array is rejected, not interpreted as unrestricted.
Code
Give a key the permissions its job needs and no more. A read-only reporting integration should not hold a scope that can cancel a subscription.
The plaintext key is returned once
The create response contains the key itself. Every later read returns metadata only: id, prefix, type, name, scopes, allowed IPs, expiry, creation time.
If you do not store it at creation, you cannot recover it. You rotate instead.
Live and test keys
key_type is sk_live or sk_test. A test key operates against the sandbox
workspace and cannot touch live data. The prefix on the key makes
which is which visible at a glance, including in a log line where it should not
have been.
Narrowing a key further
Two optional restrictions, both worth using for machine-to-machine keys:
allowed_ipslimits where the key may be presented from, as addresses or CIDR blocks. A key that leaks is useless from anywhere else.expires_atmakes the key stop working on a date. Omit it and the key lives until revoked.
Rotation and revocation
Rotate (POST /v1/api-keys/rotate) issues a replacement while the old key
keeps working, so you can deploy the new one before retiring the old. This is the
routine path, and it should be routine.
Revoke (POST /v1/api-keys/{id}/revoke) stops a key immediately. This is the
path for a key you believe is compromised, and it will break anything still using
it, which is the point.
Reference
| Topic | When you need it |
|---|---|
| Authentication | Passing the key, and the base URL |
| Team and roles | Permissions for people rather than machines |
| Workspaces | What a test key is scoped to |
| API keys API | Every field on a key |