Skip to content

API keys ​

An API key lets another system — usually your own software — talk to your Site Connect workspace without a person signing in. In Site Connect, API keys are used to manage webhooks from your own software.

Where to find it

Menu: System › API Keys · Address: hub.siteconnect.ai/api-keysWho can use it: Admins by default. Other roles need the API Keys permission: view to see keys, create to add one, delete to revoke one — see Roles and permissions. Your company also needs API access turned on (below).

Some labels aren't translated yet

A few buttons and headings on this page aren't in English yet, so this guide describes them by where they are.

Before you start: API access ​

API keys only work once API access is turned on for your company. It's off for new companies, and you can't switch it on from the hub. If the page stays empty, or creating a key shows an error, contact support and ask for API access.

Create a key ​

  1. Go to System › API Keys and click the blue button with the + at the top right. A dialog opens.

  2. Type a name in the first field — something that tells you which system uses the key.

  3. Optional: pick an expiry date in the field next to it. Leave it empty for a key that doesn't expire.

  4. Choose what the key may do by clicking scopes (selected scopes turn blue). For Site Connect, these are the ones that matter:

    • webhooks:read — see your webhooks and their delivery log. The Webhooks read button under Quick presets selects just this one.
    • webhooks:manage — add, change and delete webhooks, rotate their secrets and replay deliveries.

    The other scopes in the list belong to features that aren't part of Site Connect. Leave them unticked.

  5. Click the blue button at the bottom of the dialog. It only works once there's a name and at least one scope.

  6. A yellow box at the top of the page shows the full key. Click Copy and store it somewhere safe, such as your password manager.

You only see the key once

The yellow box is the only time the full key is shown. If you lose it, revoke the key and create a new one.

Use a key ​

Your software sends the key in an x-api-key header with each request. Each key belongs to one workspace. A key can't be used to view or create other API keys.

Check your keys ​

The table lists every key, newest first:

  • Prefix — the first characters of the key, so you can tell keys apart.
  • Scopes — the first three scopes, plus a count of the rest.
  • Expires — the expiry date, if there is one.
  • Last used — when the key was last used.
  • Status — Active or Revoked.

Dates on this page are shown day first (day/month/year).

Expired keys still say Active

Status only shows whether a key was revoked. A key past its Expires date no longer works, even though it still says Active.

Revoke a key ​

  1. Click Revoke on the key's row.
  2. Confirm with Revoke.

The key stops working straight away. This can't be undone. The key stays in the list marked Revoked.

To replace a key without downtime: create the new key, update your software to use it, then revoke the old one.

Good to know ​

  • If API access is turned off for your company, your keys can no longer be used to manage webhooks, even if they haven't been revoked.
  • Treat keys like passwords. Don't paste them into emails, chats or shared documents.

Site Connect — run your job sites from one place.