Managing API keys securely
Creating keys, choosing scopes, rotating and revoking.
3 minute read
Developer API keys look like bk_live_… and make requests on behalf of your account. You manage keys in the Developer console.
Creating#
- Give the key a name that describes what it is used for (e.g. "Server – campaign service").
- Select only the scopes you need; do not give
links:writeto an integration that only reads. - If you like, set an expiry date.
The secret is shown only once, at creation. Save it right away to a secret manager or a server environment variable.
Rotate and revoke#
- Rotate: invalidates the old secret and generates a new one with the same settings.
- Revoke: permanently cancels the key; integrations using it start receiving
401immediately.
If you suspect a secret has leaked, rotate it without delay. Do not put keys in client (browser/mobile) code or in public repositories.
Was this guide helpful?
More guides on this topic
Still not solved?
If you mention the name of this guide, we can help you faster.