← All docs

API keys

Machine-to-machine authentication for the in-account collector, separate from user login.

Creating a key

Under Administration, create an API key — it's shown once, hashed at rest, and scoped to your organisation only. Used by the in-account collector (Tier 2) to push scan results back, never for interactive login.

Revoking a key

Revoke it at any time from the same screen — takes effect immediately for any collector still using it.