Skip to content

API Keys ​

API keys let integrations -- automation tools such as n8n or Zapier, reporting scripts, or your own apps -- use the EOS Hub REST API on your behalf. Every user manages their own keys in Settings > API keys.

INFO

Read & write keys can change everything your roles allow in the web app -- team data such as to-dos, issues, Rocks, the Scorecard, and meetings (see Writing Data), and for organization Owners and Admins also the organization's settings, members, and teams (see Organization Administration). Keys themselves are managed only here, in the web app.

How a Key Works ​

A key is a long secret string that starts with ak_. An integration sends it with every request, and EOS Hub treats the request as coming from you:

  • Your current roles apply. A key sees exactly what you see in the web app, in every organization you belong to. When your roles change, the key follows immediately -- if you are removed from an organization or a team, the key loses access to it at once.
  • The key's access can only narrow your rights. A Read only key cannot change anything even if you are a team Admin.
  • Suspended organizations remain readable, like in the web app.

Creating a Key ​

  1. Open Settings and scroll to API keys.
  2. Click Create key.
  3. Enter a Name you will recognize later -- typically the integration that will use it, for example n8n reports.
  4. Choose the Access:
    • Read only -- can read everything you can see.
    • Read & write -- can also create and change data, as your role allows.
  5. Choose when the key Expires: after 30 days, 90 days (default), 365 days, or Never.
  6. Click Create key.

Copy the Key -- It Is Shown Only Once ​

After you create a key, the dialog shows the full key with a Copy button. This is the only time the key is shown. Copy it and store it right away -- in your integration's credential store or a password manager.

EOS Hub stores only a fingerprint (hash) of the key, never the key itself, so nobody -- not even the platform operator -- can show it to you again. If you lose a key, revoke it and create a new one.

WARNING

Close the dialog only after you have saved the key. Once it is closed, the key cannot be displayed again.

The Key List ​

The API keys card lists all your keys, newest first:

ColumnDescription
NameThe name you gave the key, with its visible beginning, e.g. ak_k3m7q2xa_…, so you can match it with the key stored in an integration
PermissionsRead, Write, and for platform keys Platform
Last usedWhen an integration last used the key (updated at most once a minute), or Not used yet
ExpiresThe expiry date, or Never
StatusActive, Expired, or Revoked

Expired and revoked keys stay in the list for reference but no longer work.

Revoking a Key ​

Click the trash icon next to an active key and confirm. Integrations using the key stop working immediately. Revoking cannot be undone -- to reconnect an integration, create a new key.

Revoke a key when:

  • an integration is no longer in use,
  • a key may have leaked (committed to a repository, pasted into a chat, sent by email …),
  • the person or service that had the key should no longer have access.

Limits ​

  • Each user can have at most 10 active keys. When you reach the limit, Create key is disabled -- revoke a key you no longer need first. Expired and revoked keys do not count.
  • Keys can be created and revoked only in the signed-in web app. A key can never be used to create or revoke other keys, so a leaked key cannot replace itself or lock you out.
  • Each key may make 120 requests per minute -- see Rate Limit.

Keeping Keys Safe ​

A key gives access to everything you can see in EOS Hub. Treat it like a password:

  • Prefer Read only. Choose Read & write only for integrations that really need to change data.
  • Choose a short expiry. 30 or 90 days limits the damage of a key that leaks unnoticed. Use Never only for long-running integrations you monitor.
  • One key per integration. Separate keys can be revoked independently, show their own Last used time, and have their own rate limit.
  • Never put keys in source code or in places others can read. Keep them in environment variables or a secret store.
  • Check Last used. A key that is used when you do not expect it may have leaked -- revoke it.
  • Revoke keys you no longer need.

Platform Keys ​

Platform operators (system role SUPERADMIN) see an extra option in the create dialog: Platform administration. A platform key can additionally use the platform administration endpoints -- organizations, accounts, users' API keys, and AI settings.

Because such a key controls every organization, every user, and the AI settings:

  • it can be valid for 30 or 90 days at most -- 365 days and Never are not offered;
  • it stops working for platform administration as soon as its owner is no longer a platform operator;
  • it is marked with a red Platform badge in the key list.

DANGER

Keep platform keys secret, short-lived, and out of shared tools. Revoke them as soon as the task they were created for is done.

What Platform Operators See ​

The platform operator can help when a key may have leaked. In Platform administration > Users, the API keys column shows how many active keys each user has. Clicking the count opens the user's key list -- name, visible beginning, permissions, last use, expiry, and status -- where the operator can revoke any active key.

The operator never sees the keys themselves (they are not stored), and cannot create keys on anyone's behalf.

Built with VitePress