Your firm2 min read
Manage API access for your firm’s system
Create a limited API key and replace or revoke it when needed.
Who can manage keys?
Firm admins can find API keys in firm settings. Creating or changing keys may require authenticator verification. Key creation can be disabled on a deployment.
Create a key
- Start Create key and enter a recognizable label, environment, destination system and hosting region.
- Select only the permissions needed. Available choices cover reading conversations, reading messages, listing clients and team, starting or replying to conversations, and downloading attachments.
- Choose clients and an expiry. All clients includes future clients of your firm.
- Review and create the key. Copy it immediately into the intended system’s secure configuration: the complete key is shown only once.
A key grants ongoing access within its scope until it expires or is revoked. Do not share it in client conversations or screenshots.
Replace a key
Roll key creates a replacement with the same permissions. The old key works for at most seven more days, never beyond its original expiry. Update the connected system and verify that it uses the new key.
Revoke access
Revoking one key requires typing its label to confirm. The key stops working immediately. Revoke all keys disconnects every system relying on the firm’s active keys.
Check the resulting status. An error means you cannot assume revocation succeeded.
Check usage
The list shows status, expiry and last use. Open a key for its activity. The overall activity view shows recent requests, including failed sign-in attempts. Ask support about usage you do not recognize.
View the accountant getting-started guide
Need a hand?
Ask the AirBill team through Support in the portal.