API keys and scopes
Create named, scoped API keys with optional expiry and IP allowlist, and know which scopes need an expiry.
Create keys in API keys. Name them, pick scopes, and set an expiry and an IP allowlist if you want them. Avaloi shows the secret once and stores a SHA-256 hash. The list shows the prefix and the last-used time, which updates on each successful call.
Create a key
- Open API keys. Owners, Admins, and Developers can create keys.
- Choose Create key, name it, and pick scopes.
- Set an expiry and an IP allowlist if you want them.
- Copy the secret now. It starts with
hk_live_orhk_test_. Avaloi emails you that a key was created.
Scopes
| Scope | Use |
|---|---|
sites:read |
Read sites (and GET /v1/companies/me). |
sites:write |
Change sites. |
backups:write |
Create backups. |
backups:restore_live |
Restore onto live. |
nodes:read |
Read nodes. |
nodes:write |
Change nodes. |
users:write |
Invite and change members. |
billing:read |
Read billing. No route uses it yet. |
billing:write |
Change billing. No route uses it yet. |
domains:read |
Read domains. |
dns:write |
Change DNS. |
danger:destroy |
Destroy resources. Restricted. |
support:read |
Read your company's support tickets and the replies. |
support:write |
Open a support ticket and reply on one, as the person who made the key. |
Every scope exists now, including ones whose products arrive later. A key you create today keeps working when they ship.
Restricted scopes
danger:destroy can be granted only on a key that has an expiry. Hosted MCP connections are not live yet. When they are, a connection can hold danger:destroy only when you tick it on the consent screen and your role allows it.
Revoke a key
Choose the key in the list and revoke it. Revocation takes effect within 5 seconds.
When the person who made a key leaves
A key acts as the person who made it and never does more than they can. Avaloi looks at where that person stands each time the key is used (it remembers the answer for at most 30 seconds):
- Removed from the company, or the account deleted. The key is revoked at once. The list shows it as stopped with the reason creator left, the activity log has an entry, and every owner gets a notice that lists the keys, so they can make new ones under another owner. There are no keys that belong to the company instead of a person.
- Role lowered. The key keeps only the scopes the new role may hold. The list marks it Limited by the creator's role and shows what it can still do. If the new role holds none of its scopes, the key is revoked with the reason role changed.
- Account locked out. A two-factor lockout refuses the key until the lock ends. The key is not revoked.
Owners can read the reasons in the key list ( evoked_reason and effective_scopes in GET /v1/api-keys).
Quick answers
Can I see the secret again? No. Create a new key.
My key stopped and nobody revoked it. The person who made it left the company or lost the role that held its scopes. Make a new key under another owner.
Why can I not pick danger:destroy?
Set an expiry on the key. Your role must also allow the scope.
API
GET /v1/api-keysPOST /v1/api-keysGET /v1/api-keys/currentDELETE /v1/api-keys/{id}
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.