← All docs
API keys
Machine-to-machine authentication for the in-account collector, separate from user login.
Creating a key
Under Administration, create an API key — it's shown once, hashed at rest, and scoped to your organisation only. Used by the in-account collector (Tier 2) to push scan results back, never for interactive login.
Revoking a key
Revoke it at any time from the same screen — takes effect immediately for any collector still using it.