Skip to main content
API keys are the primary method of authentication for our APIs. Each API key belongs to an organization and has permission scopes. You can also protect an API key with IP restrictions.

Create and Manage API Keys

You can generate and manage API keys in your Prem API Dashboard > Developers > API Keys section.

API keys and organizations

We issue API keys at the organization level, not to individual users. This means:
  • The API attributes each action of an API key to the owning organization.
  • Many team members can work together with separate keys in the same organization.
  • API keys stay valid independently of individual user accounts.

Unlimited Keys per Organization

Each organization can create any number of API keys. This gives flexibility across environments, services, or teams. Common usage patterns include:
  • One key per environment (e.g., development, staging, production)
  • One key per integration (e.g., billing automation, analytics)
  • Temporary keys for CI/CD or testing purposes

IP Restrictions

For better security, you can restrict an API key to specific IP addresses or subnets:
  • The restrictions support IPv4, IPv6, and CIDR notation
  • The API rejects requests from unauthorized IPs with a 403 Forbidden error
Example entries:
  • 192.168.1.10
  • 2001:0db8::/32
  • 203.0.0.0/8
Use IP allowlists to protect critical integrations (e.g., production).

Scoped Permissions

You can limit each API key to a specific set of scopes. The scopes define the parts of the API that the key can access. The dashboard asks you to set these scopes when you create an API key. If you do not specify scopes, the API key has full permissions.

API Scopes Reference

This lets you apply the principle of least privilege and isolate permissions for each use case.
A request from a key without the required scope returns 403 Forbidden.

Best Practices

  • Rotate keys regularly to decrease exposure
  • Use least privilege: assign only the required scopes
  • Restrict by IP where possible
  • Do not share keys between environments or teams
For key management, go to your Dashboard > API > API Keys. If you need help, contact support or refer to the Authentication Guide.