Skip to content

Advanced › API keys

API keys

Give a pipeline read access to exactly the environments it needs.

Create an API key

  1. Open API Keys and choose New API Key.
  2. Name it after where it will run, such as GitHub Actions – production.
  3. Choose the organization and, to narrow it down, an application and an environment.
  4. Pick the allowed actions. For CI downloads, variables:read and files:read are enough.
  5. Copy the key. It is shown only once.

How keys behave

  • Only the organization owner can create API keys for it.
  • A key is used to download variables and secure files.
  • Keys expire after 90 days by default. Delete a key to revoke it.
  • Each plan sets a monthly request quota and a per-minute limit for API keys.
  • On every use, Smart Vault checks that the key's owner still has access to that environment.