Skip to content

API keys and scopes

Create named, scoped API keys with optional expiry and IP allowlist, and know which scopes need an expiry.

Create keys in API keys. Name them, pick scopes, and set an expiry and an IP allowlist if you want them. Avaloi shows the secret once and stores a SHA-256 hash. The list shows the prefix and the last-used time, which updates on each successful call.

Create a key

  1. Open API keys. Owners, Admins, and Developers can create keys.
  2. Choose Create key, name it, and pick scopes.
  3. Set an expiry and an IP allowlist if you want them.
  4. Copy the secret now. It starts with hk_live_ or hk_test_. Avaloi emails you that a key was created.

Scopes

Scope Use
sites:read Read sites (and GET /v1/companies/me).
sites:write Change sites.
backups:write Create backups.
backups:restore_live Restore onto live.
nodes:read Read nodes.
nodes:write Change nodes.
users:write Invite and change members.
billing:read Read billing. No route uses it yet.
billing:write Change billing. No route uses it yet.
domains:read Read domains.
dns:write Change DNS.
danger:destroy Destroy resources. Restricted.
support:read Read your company's support tickets and the replies.
support:write Open a support ticket and reply on one, as the person who made the key.

Every scope exists now, including ones whose products arrive later. A key you create today keeps working when they ship.

Restricted scopes

danger:destroy can be granted only on a key that has an expiry. Hosted MCP connections are not live yet. When they are, a connection can hold danger:destroy only when you tick it on the consent screen and your role allows it.

Revoke a key

Choose the key in the list and revoke it. Revocation takes effect within 5 seconds.

When the person who made a key leaves

A key acts as the person who made it and never does more than they can. Avaloi looks at where that person stands each time the key is used (it remembers the answer for at most 30 seconds):

  • Removed from the company, or the account deleted. The key is revoked at once. The list shows it as stopped with the reason creator left, the activity log has an entry, and every owner gets a notice that lists the keys, so they can make new ones under another owner. There are no keys that belong to the company instead of a person.
  • Role lowered. The key keeps only the scopes the new role may hold. The list marks it Limited by the creator's role and shows what it can still do. If the new role holds none of its scopes, the key is revoked with the reason role changed.
  • Account locked out. A two-factor lockout refuses the key until the lock ends. The key is not revoked.

Owners can read the reasons in the key list ( evoked_reason and effective_scopes in GET /v1/api-keys).

Quick answers

Can I see the secret again? No. Create a new key.

My key stopped and nobody revoked it. The person who made it left the company or lost the role that held its scopes. Make a new key under another owner.

Why can I not pick danger:destroy? Set an expiry on the key. Your role must also allow the scope.

API

  • GET /v1/api-keys
  • POST /v1/api-keys
  • GET /v1/api-keys/current
  • DELETE /v1/api-keys/{id}

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.