Capabilities
API keys support scoped permissions per functional area:- API Keys
admin:api-keys:createadmin:api-keys:readadmin:api-keys:updateadmin:api-keys:delete
- Webhooks
admin:webhooks:createadmin:webhooks:readadmin:webhooks:delete
- Types
admin:types:createadmin:types:readadmin:types:delete
- PCI Tokens
pci:tokens:createpci:tokens:readpci:tokens:updatepci:tokens:deletepci:tokens:forward
- Network Tokens
network:tokens:createnetwork:tokens:readnetwork:tokens:deletenetwork:tokens:use
- Generic Tokens
generic:tokens:creategeneric:tokens:readgeneric:tokens:delete
Best practices
- Use the principle of least privilege — only grant necessary capabilities.
- Rotate API keys regularly for security.
- Use different keys for different services or applications.