API Key

API key metadata used to authenticate API requests.

  • Unique identifier for the object.

  • Time at which the API key was created.

  • The API key's display name.

  • values
    • secret

      Secret key used by server-side integrations.

    • publishable

      Publishable key used by client-side integrations where supported.

    • restricted

      Restricted key with a limited permission set.

  • values
    • active

      Key can authenticate requests.

    • expiring

      Key is still accepted during a rotation grace period.

    • disabled

      Key is disabled and cannot authenticate requests.

    • revoked

      Key has been revoked and cannot authenticate requests.

  • Has the value true if the object exists in live mode or the value false if the object exists in test mode.

  • Permissions granted to this API key.

  • Role associated with the key when available.

  • Present only on responses explicitly allowed to reveal the key value.

  • Redacted key value safe for display.

  • Time at which this key stops being accepted. During rotation this is set on the previous key when a grace period is used.

  • Identifier of the key this key was rotated from.

  • Identifier of the key that replaced this key during rotation.

  • Time at which this API key was last used.

  • Whether this key can be revealed through an explicit reveal endpoint.

  • Whether clients should hide the key value after the current view.

  • Number of times this API key has been used, when available.