Create and Manage API Keys
You can generate and manage API keys in your Prem API Dashboard > Developers > API Keys section.
API keys and organizations
We issue API keys at the organization level, not to individual users. This means:- The API attributes each action of an API key to the owning organization.
- Many team members can work together with separate keys in the same organization.
- API keys stay valid independently of individual user accounts.
Unlimited Keys per Organization
Each organization can create any number of API keys. This gives flexibility across environments, services, or teams. Common usage patterns include:- One key per environment (e.g.,
development,staging,production) - One key per integration (e.g., billing automation, analytics)
- Temporary keys for CI/CD or testing purposes
IP Restrictions
For better security, you can restrict an API key to specific IP addresses or subnets:- The restrictions support IPv4, IPv6, and CIDR notation
- The API rejects requests from unauthorized IPs with a
403 Forbiddenerror
192.168.1.102001:0db8::/32203.0.0.0/8
Scoped Permissions
You can limit each API key to a specific set of scopes. The scopes define the parts of the API that the key can access. The dashboard asks you to set these scopes when you create an API key. If you do not specify scopes, the API key has full permissions.API Scopes Reference
This lets you apply the principle of least privilege and isolate permissions for each use case.
A request from a key without the required scope returns
403 Forbidden.Best Practices
- Rotate keys regularly to decrease exposure
- Use least privilege: assign only the required scopes
- Restrict by IP where possible
- Do not share keys between environments or teams

