Creating a key
Keys are managed in the Pretectum app under Configuration → API Keys. Creating one asks for:
Afterwards the list shows a masked form, such as
pre_Ab3d********Xy9z, which is enough to tell your
keys apart but not to authenticate with.
What a key looks like
pre_ prefix followed by 40 alphanumeric characters. The prefix makes keys
easy to spot in logs and in secret scanners.
Using a key
Send the key in theAuthorization header:
What a key can do
A key carries no permissions of its own. It is granted access the same way a person is:- Roles decide which resources the key may act on, and which of view, add, edit and delete it may perform on each.
- Business areas decide which data the key may reach. A key with no business area assignment sees nothing, whatever its roles say.
Managing keys
You can create as many keys as you need, and it is worth using one per integration rather than sharing a single key. Each key records its own last-used timestamp, so a key that stops being used is easy to spot and safe to delete. A key can be:
Deleting a key takes effect immediately.
Error responses
Keeping keys safe
- Store keys in a secret manager or an environment variable, never in source control.
- Never put a key in client-side code, a browser request, or a URL query string. Anyone who reads it can act as your integration.
- Rotate by creating the replacement first, moving traffic to it, then deleting the old key. Keys are independent, so there is no window where neither works.
- Delete keys you no longer use.
