Aller au contenu principal
DocumentMS

Glossary

API key

Also called: API token, access key

An API key authenticates a program rather than a person. In a document system it should carry explicitly granted scopes rather than inheriting a user's permissions, so that the access an integration holds is visible and revocable without affecting anyone's account.

API key explained

Why keys should not act as users

A key that inherits a person's permissions is a key that changes behaviour when that person changes role, and stops working when they leave. It also means the integration's access cannot be reviewed separately from the person's, which defeats access review.

A key granted explicit scopes is auditable in its own right: you can state what it can do without reasoning about anyone's role membership.

The mistake most integrations make

Over-scoping. A key created to upload invoices is granted broad access because it was quicker, and it then sits in a configuration file for three years. When it leaks — in a repository, a log, a support ticket — the damage is bounded only by what it could do.

One key per integration, scoped to the minimum, is the discipline that limits the blast radius.

Rotation and revocation

Keys should be rotatable without downtime, which usually means supporting two valid keys during a changeover. Revocation should be immediate and should not require deleting a user account.

Auditing

Key creation, use and revocation should all appear in the audit trail, attributed to the key rather than to a person. An action performed by an integration and recorded as if a human did it makes the trail actively misleading.

FAQ

API key: common questions

How often should keys be rotated?

On a schedule you actually follow, and immediately on any suspicion of exposure. An annual rotation that happens beats a quarterly policy that does not.

Where should keys be stored?

In a secret manager, never in source control or a configuration file committed to a repository. Leaked keys in public repositories are one of the most common sources of unauthorised access.

Une session de 30 minutes avec un ingénieur avant-vente, sur une arborescence et une chaîne d'approbation proches des vôtres — pas un environnement de démonstration générique.