From 97ed41ab7c33e971ac95c1d7613c59434444bbbf Mon Sep 17 00:00:00 2001 From: Jenisha Patel Date: Tue, 29 Sep 2026 15:06:30 -0400 Subject: [PATCH] C34 API Keys Hardening - Docs - Changes in authentication page --- docs/concepts/authentication.mdx | 25 ++++++++++++++----------- 1 file changed, 14 insertions(+), 11 deletions(-) diff --git a/docs/concepts/authentication.mdx b/docs/concepts/authentication.mdx index 9883dc0d..4626f2fb 100644 --- a/docs/concepts/authentication.mdx +++ b/docs/concepts/authentication.mdx @@ -10,7 +10,7 @@ Requests are authenticated with **API tokens** which can be obtained using an ** - Used to generate API tokens. Does not expire. + Used to generate API tokens. Can be given an expiration date. @@ -52,18 +52,21 @@ Requests are authenticated with **API tokens** which can be obtained using an ** ### 1 - Obtaining an API key -Users can generate API keys by visiting the [Profile page](https://app.flare.io/#/profile) under the "API Keys" section. +Users can generate API keys from the [Profile page](https://app.flare.io/#/profile), in the **API keys** section, by clicking **Generate key**. - - - +When creating a key, you choose: + +- **Name**: a description that helps you recognize the key. +- **Permissions**: + - **Default**: the key inherits your current role permissions. If you can access a tenant, the key can access that tenant. If you are an organization administrator, the key has organization administrator access. If your role changes, the key's access changes with it. + - **Restricted**: the key only has the permissions you select. You can only select permissions that your role allows. +- **Expiration date** (optional): the key stops working at 00:00 (your local time) on that date. Setting an expiration date is recommended. Without one, the key never expires. + +Each endpoint in the API reference lists the API key permission it requires. -API keys are associated to a user and will have the same permissions as the user that generated them: -- If you can access a tenant, the API key will have access to that tenant. -- If you are an organization administrator, the API key will have organization administrator access. + +The key's secret is only shown once, when the key is created. Save it somewhere secure, such as a password manager or secret store. + ### 2 - Obtaining an API Token