Skip to content

API keys and scopes

Create named, scoped API keys with optional expiry and IP allowlist, and know which scopes need an expiry.

Create keys in API keys. Name them, pick scopes, and set an expiry and an IP allowlist if you want them. Avaloi shows the secret once and stores a SHA-256 hash. The list shows the prefix and the last-used time, which updates on each successful call.

Create a key

  1. Open API keys. Owners, Admins, and Developers can create keys.
  2. Choose Create key, name it, and pick scopes.
  3. Set an expiry and an IP allowlist if you want them.
  4. Copy the secret now. It starts with hk_live_ or hk_test_. Avaloi emails you that a key was created.

Scopes

Scope Use
sites:read Read sites (and GET /v1/companies/me).
sites:write Change sites.
backups:write Create backups.
backups:restore_live Restore onto live.
nodes:read Read nodes.
nodes:write Change nodes.
users:write Invite and change members.
billing:read Read billing. No route uses it yet.
billing:write Change billing. No route uses it yet.
domains:read Read domains.
dns:write Change DNS.
domains:purchase Buy a domain. Domain registration is not built yet.
domains:transfer_out Transfer a domain out. Restricted. Domain transfers are not built yet.
danger:destroy Destroy resources. Restricted.

Every scope exists now, including ones whose products arrive later. A key you create today keeps working when they ship.

Restricted scopes

danger:destroy and domains:transfer_out can be granted only on a key that has an expiry. Hosted MCP connections can hold danger:destroy when you tick it on the consent screen and your role allows it.

Revoke a key

Choose the key in the list and revoke it. Revocation takes effect within 5 seconds.

Quick answers

Can I see the secret again? No. Create a new key.

Why can I not pick danger:destroy? Set an expiry on the key. Your role must also allow the scope.

API

  • GET /v1/api-keys
  • POST /v1/api-keys
  • GET /v1/api-keys/current
  • DELETE /v1/api-keys/{id}

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.