API keys
Create, store, rotate and revoke the API keys that give your integrations access to Vestta.
On this page
API keys are created in the Vestta app, in Settings → API. That page lists every key of the workspace with its status, creation date and last use.
Who can manage keys
- The workspace must be on the Premium or Enterprise plan. On other plans the API section shows Acceso API no incluido.
- Creating, revoking, reactivating and deleting keys requires the Administrar API Keys permission. Other users can see the list but not change it.
Creating a key
Select Nueva API Key and fill in:
The full key is displayed once, in the confirmation dialog. Copy it before closing the dialog: Vestta only keeps a hash of the secret and cannot show it again.
Storing a key
- Keep keys on the server, in environment variables or a secret manager.
- Never put a key in front-end code, mobile apps, public repositories, logs or support tickets.
- Use one key per integration, so you can revoke one without affecting the others, and so Último uso (last use) tells you which integration is active.
Vestta records the date and IP address of the last successful request made with each key.
Expiry
A key stops working when its duration ends. Requests then fail with 401 API key expired. An expired key cannot be extended: create a new key and replace the old one.
The expiry date is shown in the key list. Plan the replacement before that date.
Revoking, reactivating and deleting
From the key list:
- Revocar — the key stops working immediately. Requests fail with
401 API key is revoked. - Reactivar — a revoked key accepts requests again, until its original expiry date.
- Eliminar — the key is deleted permanently. Requests fail with
401 API key not found.
Revoke a key as soon as you suspect it has leaked.
Rotating a key
Vestta has no automatic rotation. To replace a key without downtime:
Create the new key
Create a key with the same scopes as the one you are replacing.
Deploy it
Update the secret in your integration and deploy.
Verify it
Call Retrieve key context with the new key and check the scopes in the response. Último uso of the new key starts updating.
Revoke the old key
Revoke the old key once Último uso shows it is no longer used. Delete it later, when you are sure nothing depends on it.