HELP / YOUR ACCOUNT

Create and rotate API keys

Replace a key safely, choose a handover and understand what revocation changes.

Copy the secret once

Create a named key for the application that will use it. pageflock shows the full secret when it is created and stores its hash. Copy it to your server’s secret storage then; the masked key in the workspace cannot reveal the original value later.

Keep keys out of frontend code, screenshots, source control, logs and support messages. All keys for the same account share the credit balance and account limits.

Choose a handover

Rotation creates a replacement key. A 24-hour handover keeps the previous key valid temporarily while you update your application. Copy the replacement, update every process that uses the old key and verify that those applications work with the replacement.

The old key expires at the handover deadline. If you suspect the secret has been exposed, choose immediate replacement or revoke the old key instead of leaving it active for the handover. Requests using an expired or revoked key cannot authenticate.

Review usage

Key metadata helps you recognize creation time, expiry and recent use without revealing the secret. A key that an application still uses needs a coordinated update before revocation; changing your display name or signing out is not a key rotation.

If you lose the replacement secret before storing it, create or rotate another key. Do not ask support to recover the plaintext value; it is not stored.

YOUR PRIVACY

Choose what works for you. You can reopen these settings from the footer at any time.