Glossary
API key
Also called: API token, access key
An API key authenticates a program rather than a person. In a document system it should carry explicitly granted scopes rather than inheriting a user's permissions, so that the access an integration holds is visible and revocable without affecting anyone's account.
API key explained
Why keys should not act as users
A key that inherits a person's permissions is a key that changes behaviour when that person changes role, and stops working when they leave. It also means the integration's access cannot be reviewed separately from the person's, which defeats access review.
A key granted explicit scopes is auditable in its own right: you can state what it can do without reasoning about anyone's role membership.
The mistake most integrations make
Over-scoping. A key created to upload invoices is granted broad access because it was quicker, and it then sits in a configuration file for three years. When it leaks — in a repository, a log, a support ticket — the damage is bounded only by what it could do.
One key per integration, scoped to the minimum, is the discipline that limits the blast radius.
Rotation and revocation
Keys should be rotatable without downtime, which usually means supporting two valid keys during a changeover. Revocation should be immediate and should not require deleting a user account.
Auditing
Key creation, use and revocation should all appear in the audit trail, attributed to the key rather than to a person. An action performed by an integration and recorded as if a human did it makes the trail actively misleading.
FAQ
API key: common questions
How often should keys be rotated?
On a schedule you actually follow, and immediately on any suspicion of exposure. An annual rotation that happens beats a quarterly policy that does not.
Where should keys be stored?
In a secret manager, never in source control or a configuration file committed to a repository. Leaked keys in public repositories are one of the most common sources of unauthorised access.
Related terms
- Access reviewAn access review is a periodic check that the people who have access to something still need it.
- Break-glass accessBreak-glass access is a deliberate, time-boxed grant of permissions a user does not normally hold, for genuine emergencies.
- Data residencyData residency is the commitment that data is stored and processed within a specified country or region.
- Encryption at restEncryption at rest protects stored data by encrypting it on disk, so that physical access to the storage medium does not yield readable content.
- Permission inheritancePermission inheritance means a document takes its access rights from the folder containing it, rather than being permissioned individually.
- Role-based access controlRole-based access control grants permissions to roles rather than to individuals, and assigns people to roles.
最終レビュー: 2026年8月28日. Browse the full glossary.