Skip to content

Loading…

API keys

Create, store, rotate and revoke the API keys that give your integrations access to Vestta.

On this page

API keys are created in the Vestta app, in Settings → API. That page lists every key of the workspace with its status, creation date and last use.

Who can manage keys

  • The workspace must be on the Premium or Enterprise plan. On other plans the API section shows Acceso API no incluido.
  • Creating, revoking, reactivating and deleting keys requires the Administrar API Keys permission. Other users can see the list but not change it.

Creating a key

Select Nueva API Key and fill in:

FieldMeaning
NombreA label for the integration that will use the key, such as Website or Zapier.
Duración1, 3, 6 or 12 months. Each month counts as 30 days from the moment of creation.
PermisosThe scopes of the key.

The full key is displayed once, in the confirmation dialog. Copy it before closing the dialog: Vestta only keeps a hash of the secret and cannot show it again.

Storing a key

  • Keep keys on the server, in environment variables or a secret manager.
  • Never put a key in front-end code, mobile apps, public repositories, logs or support tickets.
  • Use one key per integration, so you can revoke one without affecting the others, and so Último uso (last use) tells you which integration is active.

Vestta records the date and IP address of the last successful request made with each key.

Expiry

A key stops working when its duration ends. Requests then fail with 401 API key expired. An expired key cannot be extended: create a new key and replace the old one.

The expiry date is shown in the key list. Plan the replacement before that date.

Revoking, reactivating and deleting

From the key list:

  • Revocar — the key stops working immediately. Requests fail with 401 API key is revoked.
  • Reactivar — a revoked key accepts requests again, until its original expiry date.
  • Eliminar — the key is deleted permanently. Requests fail with 401 API key not found.

Revoke a key as soon as you suspect it has leaked.

Rotating a key

Vestta has no automatic rotation. To replace a key without downtime:

Create the new key

Create a key with the same scopes as the one you are replacing.

Deploy it

Update the secret in your integration and deploy.

Verify it

Call Retrieve key context with the new key and check the scopes in the response. Último uso of the new key starts updating.

Revoke the old key

Revoke the old key once Último uso shows it is no longer used. Delete it later, when you are sure nothing depends on it.