API keys and scopes
Create named, scoped API keys with optional expiry and IP allowlist, and know which scopes need an expiry.
Create keys in API keys. Name them, pick scopes, and set an expiry and an IP allowlist if you want them. Avaloi shows the secret once and stores a SHA-256 hash. The list shows the prefix and the last-used time, which updates on each successful call.
Create a key
- Open API keys. Owners, Admins, and Developers can create keys.
- Choose Create key, name it, and pick scopes.
- Set an expiry and an IP allowlist if you want them.
- Copy the secret now. It starts with
hk_live_orhk_test_. Avaloi emails you that a key was created.
Scopes
| Scope | Use |
|---|---|
sites:read |
Read sites (and GET /v1/companies/me). |
sites:write |
Change sites. |
backups:write |
Create backups. |
backups:restore_live |
Restore onto live. |
nodes:read |
Read nodes. |
nodes:write |
Change nodes. |
users:write |
Invite and change members. |
billing:read |
Read billing. No route uses it yet. |
billing:write |
Change billing. No route uses it yet. |
domains:read |
Read domains. |
dns:write |
Change DNS. |
domains:purchase |
Buy a domain. Domain registration is not built yet. |
domains:transfer_out |
Transfer a domain out. Restricted. Domain transfers are not built yet. |
danger:destroy |
Destroy resources. Restricted. |
Every scope exists now, including ones whose products arrive later. A key you create today keeps working when they ship.
Restricted scopes
danger:destroy and domains:transfer_out can be granted only on a key that has an expiry. Hosted MCP connections can hold danger:destroy when you tick it on the consent screen and your role allows it.
Revoke a key
Choose the key in the list and revoke it. Revocation takes effect within 5 seconds.
Quick answers
Can I see the secret again? No. Create a new key.
Why can I not pick danger:destroy?
Set an expiry on the key. Your role must also allow the scope.
API
GET /v1/api-keysPOST /v1/api-keysGET /v1/api-keys/currentDELETE /v1/api-keys/{id}
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.