Skip to content
API and developers

Managing API keys securely

Creating keys, choosing scopes, rotating and revoking.

3 minute read

Developer API keys look like bk_live_… and make requests on behalf of your account. You manage keys in the Developer console.

Creating#

  • Give the key a name that describes what it is used for (e.g. "Server – campaign service").
  • Select only the scopes you need; do not give links:write to an integration that only reads.
  • If you like, set an expiry date.

The secret is shown only once, at creation. Save it right away to a secret manager or a server environment variable.

Rotate and revoke#

  • Rotate: invalidates the old secret and generates a new one with the same settings.
  • Revoke: permanently cancels the key; integrations using it start receiving 401 immediately.

If you suspect a secret has leaked, rotate it without delay. Do not put keys in client (browser/mobile) code or in public repositories.

Was this guide helpful?

Still not solved?

If you mention the name of this guide, we can help you faster.

Contact support