Skip to main content

Create an API key

An API key gives programmatic access to your project resources — a CI/CD pipeline, a script, an external service calling an agent.

Every API key belongs to a service account, which is the principal that holds the roles the key authenticates as. Creating a key here creates that service account for you, named after the key. A key you create from the Security section the other way round, by opening a service account first, is listed on this page too. Use the Security route when the software needs an identity you will grant specific roles to. Learn more: Manage users and service accounts.

Create the key​

  1. Go to the Settings section under Administration in the navigation panel.
  2. Open the API keys page.
  3. Click New. This opens the "Create API Key" dialog.
  4. Enter a description in the Description field, for example, "CI/CD pipeline key." This is how you identify the key later, so name the consumer rather than the date.
  5. Set the scope of the key: "Project-wide," or "Specific agent" to limit it to one agent.
  6. Set the Expiration field: "Never," "30 days," "90 days," or "1 year."
  7. Click Create.
  8. Copy the key in the "API Key Created" dialog, then click Done. This is the only time the full key is shown.

As a result, Creatio AI Studio issues the key and lists it with its description and status, the masked key, the agent, the owner, and the date it was issued.

Important

Copy the key before you close the dialog. Creatio AI Studio never shows the full key again — Show on the list reveals only its prefix, such as csp_mNVK, which identifies the key but cannot authenticate with it. A key you did not copy has to be rotated or replaced.

Treat a key like a production secret even in a sandbox. Anyone holding it has the access it carries, and keys belong to the whole workspace rather than to one environment, so revoking one affects every environment at once.

Manage an existing key​

Action

Effect

Show, Copy

Reveals the key's prefix and copies it. The prefix tells you which key a row is, and cannot be used to authenticate.

Rotate

Issues a replacement. Use it on a schedule, and whenever a key may have been exposed.

Revoke

Stops the key working. The status changes to "Revoked."

A key's status is "Active," "Revoked," or "Expired."


See also​

Manage users and service accounts

Connect a model provider

Creatio AI Studio overview