Create and manage space API keys

The API Keys section is visible when the space has Pro access. You also need permission to manage that space. Keys created here are tied to this space; they do not grant unrestricted platform access.

Create a key

  1. Open API Keys and select Create API Key.
  2. Enter a descriptive Name, such as Website job board.
  3. Select the permissions your integration needs. Choose read access for displaying data and job write access only if it must create or unpublish jobs.
  4. Optionally set Expires in (days) and an IP whitelist of your server’s outgoing IP addresses.
  5. Select Create Key.
  6. Copy the complete key immediately. It is only revealed at creation or rotation; the normal list shows a masked key.
  7. Store it in your server’s secret configuration and make the first read request from the API quick start.

Read-only permissions produce a restricted key; write permissions produce a live key. These labels describe key permissions, not a separate testing environment.

Use X-API-Key or Authorization: Bearer headers. Keep keys out of public browser scripts, repositories, screenshots and URLs.

Review, rotate or revoke

The list shows status, permissions, creation, last use and request count, with expiry information when set.

  • Rotate replaces the selected key with a new secret and revokes the old one. Update your integration immediately; there is no overlap period promised by this action.
  • Revoke immediately removes access for applications using the key. Read the confirmation and make sure you chose the right key.

If you lose the complete secret, create a replacement or rotate it. If an integration returns 401, check whether the key is active, expired or revoked and whether its IP restriction matches the requesting server. For 403, check permissions and space scope.

See API authentication and errors for examples.