Advanced › API keys
API keys
Give a pipeline read access to exactly the environments it needs.
Create an API key
- Open API Keys and choose New API Key.
- Name it after where it will run, such as
GitHub Actions – production. - Choose the organization and, to narrow it down, an application and an environment.
- Pick the allowed actions. For CI downloads,
variables:readandfiles:readare enough. - Copy the key. It is shown only once.
How keys behave
- Only the organization owner can create API keys for it.
- A key is used to download variables and secure files.
- Keys expire after 90 days by default. Delete a key to revoke it.
- Each plan sets a monthly request quota and a per-minute limit for API keys.
- On every use, Smart Vault checks that the key's owner still has access to that environment.
Tip
store the key in your CI secret store, never in the repository.