Create an API key

Create an environment-specific API key with the permissions and expiry your backend needs. You need access to API keys in the intended workspace.

Open API keys

In Developer portal, open API keys. The Mock API keys section is for sandbox testing; use Production API keys for production requests. Create separate keys for these purposes.

Set the key’s access and expiry

Choose Generate new API key for the intended environment. Enter a label you can recognize later, such as “Acme Trading — sandbox invoices”. Select Read if the application only retrieves information. Select Write as well if it submits invoices or changes data. Choose an expiry period or a custom expiry date before creating the key.

Copy the secret

Create the key, then copy the full secret from the dialog into your server-side secret manager. It is shown only once. The key appears in the API keys list afterward, but the list does not reveal the secret again. If you close the dialog without saving it, revoke the key and create a replacement.

Use or replace the key

The authentication header depends on the API you call. See Authentication and environments for the header names and the way each request selects sandbox or production. Never send both authentication headers in one request.

To replace an exposed or unneeded key, generate and deploy a replacement first, then choose Revoke on the old key and confirm. Revoked and expired keys cannot authenticate. Do not share a key in a support request.

If something goes wrong

You cannot open API keys: confirm the selected workspace and ask a workspace administrator to check your access.

The request returns 401: check that you copied the full secret, use the authentication header required by that API, and check whether the key is expired or revoked. Create a replacement if needed.

The request returns 403: check the key’s permissions and environment against the operation. A sandbox key cannot authorize a production request. Create a key with the required access instead of changing the request to bypass the restriction.

Next, create an integration with a sandbox sample payload.

Last updated