Managing API keys
An API key is what your integration uses to get access tokens for Walley's APIs. Create and remove keys on the API keys tab in Manage Organization.
Before you start​
- You need the Api key Management permission.
- Open Manage Organization. Select your name in the top right and pick it from the menu.
- Read Authentication to see how the key is exchanged for an access token.
Create an API key​
By default, your organization can have up to 10 active API keys at the same time.
- Open the API keys tab.
- Select Create new and then Api key. If your organization has no keys yet, the tab shows a Create Api key button instead.
- Optionally, enter a Key label so you can tell the key apart from the others.
- Choose the Expiration time. The key stops working after that time.
- Select Create.
- Copy the Client ID and Secret from the dialog and store them in a safe location. The secret is shown only once, and you need both to get an access token.
Rotate keys before they expire
Set a short expiry and rotate keys at least once a year, more often if you can. Rotate before the expiry date so your integration never stops working.
Remove an API key​
Removing a key cannot be undone
Any integration that uses the key stops working as soon as you remove it.
- Find the key in the list.
- Select Remove on that row.
- Confirm the removal.