API Key Management and Scoping
Creating Scoped API Keys
Create API keys with the minimum permissions required for their use case. Every key should specify both resource scopes (which resources it can access) and action scopes (what operations it can perform). Create a key via POST /org/api-keys with {"name": "CI Pipeline Scanner", "scopes": ["scans:write", "scans:read", "reports:read"], "expires_at": "2025-12-31T23:59:59Z"}.
Keys can be further scoped to specific projects or environments: {"name": "Prod Monitor", "scopes": ["alerts:read"], "resource_filter": {"project_ids": ["proj_abc"], "environments": ["production"]}}. A key with project-scoped permissions cannot access resources in other projects, even if the key owner has broader organizational permissions.
Key Rotation
Rotate API keys regularly (recommended: every 90 days) or immediately upon suspected compromise. The platform supports graceful rotation with overlap periods. Call POST /org/api-keys/:id/rotate to generate a new key while keeping the old key active. The response includes both the new key and the old key's expiration time (default: 24 hours). Update your applications to use the new key, then call DELETE /org/api-keys/:id/old to revoke the old key immediately.
Set up automated rotation alerts: configure the platform to send notifications 14 days before a key expires via PUT /org/api-keys/:id with {"expiry_notification_days": 14}. The notification is sent to the key creator and all organization admins via email and webhook.
Monitoring and Revocation
Monitor API key usage in real time via GET /org/api-keys/:id/usage which returns request counts, last used timestamp, unique source IPs, and error rates. Set up anomaly alerts that trigger when a key's usage pattern changes significantly, such as requests from a new IP range or a sudden increase in error rates.
Revoke a compromised key immediately via DELETE /org/api-keys/:id. Revocation is instant and global: all in-flight requests using the revoked key receive a 401 Unauthorized response. The audit log records the revocation event including who revoked the key and the reason. For bulk operations, revoke all keys matching a filter: POST /org/api-keys/revoke-batch with {"filter": {"created_before": "2025-01-01"}}.
Links in this article were last verified on March 2025.