API keys

Create scoped keys per project and environment, see the secret once, and roll or revoke them later.

An API key authenticates the REST API and the SDK. Every key belongs to one project and one environment, and carries one access level.

The API keys page for Acme Desk, listing keys with their access level, environment and last-used time

Access levels

LevelCan do
Full accessEverything, including arc0.connections.export
Connect links onlyarc0.connect.createLink and nothing else
Read-onlyList and get calls — no runs, no writes

Give a key the narrowest level that does the job. A key you paste into a script that only generates connect links for new signups should carry Connect links only, not Full access.

Environments and prefixes

A key is a production key or a development key, never both, and the prefix tells you which at a glance:

  • a0_live_ — production
  • a0_test_ — development

The secret is the prefix plus 32 characters. The table only ever shows the prefix and the first few characters, like a0_live_7Hq2•••• — the rest is never shown again after creation.

Creating a key

Open the create dialog

From API keys, click Create key. Give it a name that says what it's for — billing-worker, not key-3.

The Create API key dialog with fields for name, access level and expiry
Name, access level, and an optional expiry.

Set the access level and expiry

Pick Full access, Connect links only or Read-only, and an expiry: Never, 30 days, 90 days or 1 year. An expiring key is a good default for anything short-lived, like a migration script.

Click Create key.

Copy the secret

The full secret is shown exactly once.

The key-created screen showing the full secret once, with a copy button
Arc0 keeps only a hash — this is the only time you'll see the full key.

Store it as ARC0_API_KEY before you close this dialog. Arc0 keeps only a hash, so there's no way to recover it later — you'd have to roll the key and update every caller.

Click I've stored it once it's saved somewhere real.

Rolling and revoking

Each key's row menu has three actions:

  • Rename — changes the label, not the secret.
  • Roll key — issues a new secret under the same name, access level and environment, and invalidates the old one. Use this if a key may have leaked but callers still need to keep working once you update it.
  • Revoke key — invalidates the secret immediately, with no replacement. A revoked key shows Revoked {time} and can't be un-revoked.

On this page