[{"data":1,"prerenderedAt":295},["ShallowReactive",2],{"page:\u002Fapi-keys":3},{"id":4,"title":5,"body":6,"description":285,"extension":286,"meta":287,"navigation":288,"operation":289,"path":290,"rawbody":291,"seo":292,"stem":293,"__hash__":294},"docs\u002Fapi-keys.md","API keys",{"type":7,"value":8,"toc":269},"minimark",[9,24,29,56,60,67,129,136,146,150,165,168,172,179,182,186,189,215,218,222,225],[10,11,12,13,23],"p",{},"API keys are created in the Vestta app, in ",[14,15,19],"a",{"href":16,"rel":17},"https:\u002F\u002Fcrm.vestta.app\u002Fsettings?page=apis",[18],"nofollow",[20,21,22],"strong",{},"Settings → API",". That page lists every key of the workspace with its status, creation date and last use.",[25,26,28],"h2",{"id":27},"who-can-manage-keys","Who can manage keys",[30,31,32,49],"ul",{},[33,34,35,36,39,40,43,44,48],"li",{},"The workspace must be on the ",[20,37,38],{},"Premium"," or ",[20,41,42],{},"Enterprise"," plan. On other plans the API section shows ",[45,46,47],"em",{},"Acceso API no incluido",".",[33,50,51,52,55],{},"Creating, revoking, reactivating and deleting keys requires the ",[20,53,54],{},"Administrar API Keys"," permission. Other users can see the list but not change it.",[25,57,59],{"id":58},"creating-a-key","Creating a key",[10,61,62,63,66],{},"Select ",[20,64,65],{},"Nueva API Key"," and fill in:",[68,69,70,83],"table",{},[71,72,73],"thead",{},[74,75,76,80],"tr",{},[77,78,79],"th",{},"Field",[77,81,82],{},"Meaning",[84,85,86,104,114],"tbody",{},[74,87,88,94],{},[89,90,91],"td",{},[20,92,93],{},"Nombre",[89,95,96,97,39,101,48],{},"A label for the integration that will use the key, such as ",[98,99,100],"code",{},"Website",[98,102,103],{},"Zapier",[74,105,106,111],{},[89,107,108],{},[20,109,110],{},"Duración",[89,112,113],{},"1, 3, 6 or 12 months. Each month counts as 30 days from the moment of creation.",[74,115,116,121],{},[89,117,118],{},[20,119,120],{},"Permisos",[89,122,123,124,128],{},"The ",[14,125,127],{"href":126},"\u002Fauthentication#scopes","scopes"," of the key.",[10,130,131,132,135],{},"The full key is displayed ",[20,133,134],{},"once",", in the confirmation dialog. Copy it before closing the dialog: Vestta only keeps a hash of the secret and cannot show it again.",[137,138,139],"warning",{},[10,140,141,142,48],{},"Always select at least one scope. A key without scopes can only call ",[14,143,145],{"href":144},"\u002Fme","Retrieve key context",[25,147,149],{"id":148},"storing-a-key","Storing a key",[30,151,152,155,158],{},[33,153,154],{},"Keep keys on the server, in environment variables or a secret manager.",[33,156,157],{},"Never put a key in front-end code, mobile apps, public repositories, logs or support tickets.",[33,159,160,161,164],{},"Use one key per integration, so you can revoke one without affecting the others, and so ",[20,162,163],{},"Último uso"," (last use) tells you which integration is active.",[10,166,167],{},"Vestta records the date and IP address of the last successful request made with each key.",[25,169,171],{"id":170},"expiry","Expiry",[10,173,174,175,178],{},"A key stops working when its duration ends. Requests then fail with ",[98,176,177],{},"401 API key expired",". An expired key cannot be extended: create a new key and replace the old one.",[10,180,181],{},"The expiry date is shown in the key list. Plan the replacement before that date.",[25,183,185],{"id":184},"revoking-reactivating-and-deleting","Revoking, reactivating and deleting",[10,187,188],{},"From the key list:",[30,190,191,200,206],{},[33,192,193,196,197,48],{},[20,194,195],{},"Revocar"," — the key stops working immediately. Requests fail with ",[98,198,199],{},"401 API key is revoked",[33,201,202,205],{},[20,203,204],{},"Reactivar"," — a revoked key accepts requests again, until its original expiry date.",[33,207,208,211,212,48],{},[20,209,210],{},"Eliminar"," — the key is deleted permanently. Requests fail with ",[98,213,214],{},"401 API key not found",[10,216,217],{},"Revoke a key as soon as you suspect it has leaked.",[25,219,221],{"id":220},"rotating-a-key","Rotating a key",[10,223,224],{},"Vestta has no automatic rotation. To replace a key without downtime:",[226,227,228,233,236,240,243,247,259,263],"steps",{},[229,230,232],"h3",{"id":231},"create-the-new-key","Create the new key",[10,234,235],{},"Create a key with the same scopes as the one you are replacing.",[229,237,239],{"id":238},"deploy-it","Deploy it",[10,241,242],{},"Update the secret in your integration and deploy.",[229,244,246],{"id":245},"verify-it","Verify it",[10,248,249,250,252,253,255,256,258],{},"Call ",[14,251,145],{"href":144}," with the new key and check the ",[98,254,127],{}," in the response. ",[20,257,163],{}," of the new key starts updating.",[229,260,262],{"id":261},"revoke-the-old-key","Revoke the old key",[10,264,265,266,268],{},"Revoke the old key once ",[20,267,163],{}," shows it is no longer used. Delete it later, when you are sure nothing depends on it.",{"title":270,"searchDepth":271,"depth":271,"links":272},"",3,[273,275,276,277,278,279],{"id":27,"depth":274,"text":28},2,{"id":58,"depth":274,"text":59},{"id":148,"depth":274,"text":149},{"id":170,"depth":274,"text":171},{"id":184,"depth":274,"text":185},{"id":220,"depth":274,"text":221,"children":280},[281,282,283,284],{"id":231,"depth":271,"text":232},{"id":238,"depth":271,"text":239},{"id":245,"depth":271,"text":246},{"id":261,"depth":271,"text":262},"Create, store, rotate and revoke the API keys that give your integrations access to Vestta.","md",{},true,null,"\u002Fapi-keys","---\ntitle: API keys\ndescription: Create, store, rotate and revoke the API keys that give your integrations access to Vestta.\n---\n\nAPI keys are created in the Vestta app, in [**Settings → API**](https:\u002F\u002Fcrm.vestta.app\u002Fsettings?page=apis). That page lists every key of the workspace with its status, creation date and last use.\n\n## Who can manage keys\n\n- The workspace must be on the **Premium** or **Enterprise** plan. On other plans the API section shows *Acceso API no incluido*.\n- Creating, revoking, reactivating and deleting keys requires the **Administrar API Keys** permission. Other users can see the list but not change it.\n\n## Creating a key\n\nSelect **Nueva API Key** and fill in:\n\n| Field | Meaning |\n| --- | --- |\n| **Nombre** | A label for the integration that will use the key, such as `Website` or `Zapier`. |\n| **Duración** | 1, 3, 6 or 12 months. Each month counts as 30 days from the moment of creation. |\n| **Permisos** | The [scopes](\u002Fauthentication#scopes) of the key. |\n\nThe full key is displayed **once**, in the confirmation dialog. Copy it before closing the dialog: Vestta only keeps a hash of the secret and cannot show it again.\n\n::warning\nAlways select at least one scope. A key without scopes can only call [Retrieve key context](\u002Fme).\n::\n\n## Storing a key\n\n- Keep keys on the server, in environment variables or a secret manager.\n- Never put a key in front-end code, mobile apps, public repositories, logs or support tickets.\n- Use one key per integration, so you can revoke one without affecting the others, and so **Último uso** (last use) tells you which integration is active.\n\nVestta records the date and IP address of the last successful request made with each key.\n\n## Expiry\n\nA key stops working when its duration ends. Requests then fail with `401 API key expired`. An expired key cannot be extended: create a new key and replace the old one.\n\nThe expiry date is shown in the key list. Plan the replacement before that date.\n\n## Revoking, reactivating and deleting\n\nFrom the key list:\n\n- **Revocar** — the key stops working immediately. Requests fail with `401 API key is revoked`.\n- **Reactivar** — a revoked key accepts requests again, until its original expiry date.\n- **Eliminar** — the key is deleted permanently. Requests fail with `401 API key not found`.\n\nRevoke a key as soon as you suspect it has leaked.\n\n## Rotating a key\n\nVestta has no automatic rotation. To replace a key without downtime:\n\n:::steps\n### Create the new key\n\nCreate a key with the same scopes as the one you are replacing.\n\n### Deploy it\n\nUpdate the secret in your integration and deploy.\n\n### Verify it\n\nCall [Retrieve key context](\u002Fme) with the new key and check the `scopes` in the response. **Último uso** of the new key starts updating.\n\n### Revoke the old key\n\nRevoke the old key once **Último uso** shows it is no longer used. Delete it later, when you are sure nothing depends on it.\n:::\n",{"title":5,"description":285},"api-keys","Inx8ThyiK5LbvJCCs0T6g75EkM2uQaO7Kru-F8HoRZM",1791110048686]