[{"data":1,"prerenderedAt":47},["ShallowReactive",2],{"docs:rendered-article:\u002Fdocs\u002Fpublic\u002Fguides\u002Fapi-key-management":3},{"path":4,"slug":5,"title":8,"description":9,"category":6,"categoryLabel":10,"order":11,"status":12,"family":13,"subfamily":13,"content":14,"html":15,"examplesHtml":16,"excerpt":17,"readTimeMinutes":18,"headings":19,"examplesHeadings":42,"lastUpdated":13,"endpointId":13,"requiredFlag":13,"relatedArticlePaths":43,"badge":13},"\u002Fdocs\u002Fguides\u002Fapi-key-management",[6,7],"guides","api-key-management","API key management","Create, configure, and secure API keys with permissions, rate limits, and expiration.","Guides",12,"updated",null,"\nYour keys work out of the box with full access and no configuration needed. This guide covers optional features you can use as your integration grows.\n\n> [!TIP]\n> Don't have an API key yet? Start with [Authentication](\u002Fdocs\u002Fauthentication).\n\n## 1. Create a key\n\n1. Open **[API Keys](\u002Fapi-keys)** in the dashboard.\n2. Click **Create API Key** and give it a name (e.g. `prod-backend`, `staging-sync`).\n3. Copy and store it securely.\n\nThat's it: your key is ready to use with full access to all endpoints.\n\n## 2. Fine-tune permissions (optional)\n\nBy default, every key has **full access**. No setup needed. As your team grows, you can scope each key to specific capabilities:\n\n| Scope                | What it covers                                            |\n| -------------------- | --------------------------------------------------------- |\n| Person Enrichment    | Enrich person profiles from Social URLs                 |\n| Person Activities    | Fetch posts, comments, and reactions for people |\n| Company Enrichment   | Enrich company profiles from Social URLs or domains     |\n| Company Activities   | Fetch posts and activities for companies         |\n| Search               | Search for people and companies                           |\n| Contact (Email)      | Find and verify email addresses                           |\n| Posts                | Fetch individual posts and their activities               |\n\nSelect only the scopes your integration needs, or leave them all checked for full access.\n\n> [!NOTE]\n> Free endpoints like `GET \u002Fv2\u002Fusage` are always accessible, regardless of permissions.\n\nIf a key tries to call an endpoint outside its scopes, the API returns a `403` status code.\n\n## 3. Set rate limits (optional)\n\nPer-key rate limits let you protect your workspace budget by capping individual integrations:\n\n| Setting     | Description                               |\n| ----------- | ----------------------------------------- |\n| RPM limit   | Maximum requests per minute for this key  |\n| Daily limit | Maximum requests per day for this key     |\n\nIf you don't set any, your workspace defaults apply automatically. Per-key limits can only cap usage below the workspace maximum. They can never exceed it.\n\nWhen a per-key limit is reached, the API returns `429 Too Many Requests`.\n\n## 4. Add an expiration date (optional)\n\nUseful for temporary access: contractor keys, demo integrations, or test environments. After the date you choose, the key stops working automatically.\n\nYou can change or remove the expiration anytime by editing the key.\n\n## Manage existing keys\n\n**Edit.** Click the edit icon on any active key to update its name, permissions, rate limits, or expiration. Changes take effect immediately.\n\n**Revoke.** Revoked keys stop working immediately. They stay visible in the table for reference, but cannot be reactivated. When in doubt, create a new key first, update your integration, then revoke the old one.\n\n## Quick tips\n\n- **One key per environment.** Separate keys for dev, staging, and production keep things clean.\n- **Name keys clearly.** A name like `prod-crm-sync` or `staging-enrichment` makes auditing easy.\n- **Scope when you need to.** Start with full access. Restrict later as your team and integrations grow.\n\n## Something not working?\n\n| Symptom | Fix |\n| ------- | --- |\n| `403 Forbidden` | The key is missing a required permission. Edit it in [API Keys](\u002Fapi-keys) |\n| `429 Too Many Requests` | A per-key rate limit was reached. Raise it or wait for the reset |\n| `401 Unauthorized` (expired key) | The key passed its expiration date. Create a new one |\n\nFor all error codes and retry strategies, see [Error handling & retries](\u002Fdocs\u002Fguides\u002Ferrors-retries).\n","\u003Cp>Your keys work out of the box with full access and no configuration needed. This guide covers optional features you can use as your integration grows.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cp class=\"markdown-alert-title\">\u003Csvg class=\"octicon octicon-light-bulb mr-2\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\">\u003Cpath d=\"M8 1.5c-2.363 0-4 1.69-4 3.75 0 .984.424 1.625.984 2.304l.214.253c.223.264.47.556.673.848.284.411.537.896.621 1.49a.75.75 0 0 1-1.484.211c-.04-.282-.163-.547-.37-.847a8.456 8.456 0 0 0-.542-.68c-.084-.1-.173-.205-.268-.32C3.201 7.75 2.5 6.766 2.5 5.25 2.5 2.31 4.863 0 8 0s5.5 2.31 5.5 5.25c0 1.516-.701 2.5-1.328 3.259-.095.115-.184.22-.268.319-.207.245-.383.453-.541.681-.208.3-.33.565-.37.847a.751.751 0 0 1-1.485-.212c.084-.593.337-1.078.621-1.489.203-.292.45-.584.673-.848.075-.088.147-.173.213-.253.561-.679.985-1.32.985-2.304 0-2.06-1.637-3.75-4-3.75ZM5.75 12h4.5a.75.75 0 0 1 0 1.5h-4.5a.75.75 0 0 1 0-1.5ZM6 15.25a.75.75 0 0 1 .75-.75h2.5a.75.75 0 0 1 0 1.5h-2.5a.75.75 0 0 1-.75-.75Z\">\u003C\u002Fpath>\u003C\u002Fsvg>Tip\u003C\u002Fp>\u003Cp>Don’t have an API key yet? Start with \u003Ca href=\"\u002Fdocs\u002Fauthentication\">Authentication\u003C\u002Fa>.\u003C\u002Fp>\n\u003C\u002Fdiv>\n\u003Ch2 id=\"1-create-a-key\">1. Create a key\u003C\u002Fh2>\n\u003Col>\n\u003Cli>Open \u003Cstrong>\u003Ca href=\"\u002Fapi-keys\" target=\"_blank\" rel=\"noopener\">API Keys\u003C\u002Fa>\u003C\u002Fstrong> in the dashboard.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Create API Key\u003C\u002Fstrong> and give it a name (e.g. \u003Ccode>prod-backend\u003C\u002Fcode>, \u003Ccode>staging-sync\u003C\u002Fcode>).\u003C\u002Fli>\n\u003Cli>Copy and store it securely.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>That’s it: your key is ready to use with full access to all endpoints.\u003C\u002Fp>\n\u003Ch2 id=\"2-fine-tune-permissions-optional\">2. Fine-tune permissions (optional)\u003C\u002Fh2>\n\u003Cp>By default, every key has \u003Cstrong>full access\u003C\u002Fstrong>. No setup needed. As your team grows, you can scope each key to specific capabilities:\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Scope\u003C\u002Fth>\n\u003Cth>What it covers\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>Person Enrichment\u003C\u002Ftd>\n\u003Ctd>Enrich person profiles from Social URLs\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Person Activities\u003C\u002Ftd>\n\u003Ctd>Fetch posts, comments, and reactions for people\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Company Enrichment\u003C\u002Ftd>\n\u003Ctd>Enrich company profiles from Social URLs or domains\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Company Activities\u003C\u002Ftd>\n\u003Ctd>Fetch posts and activities for companies\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Search\u003C\u002Ftd>\n\u003Ctd>Search for people and companies\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Contact (Email)\u003C\u002Ftd>\n\u003Ctd>Find and verify email addresses\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Posts\u003C\u002Ftd>\n\u003Ctd>Fetch individual posts and their activities\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003Cp>Select only the scopes your integration needs, or leave them all checked for full access.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-note\">\u003Cp class=\"markdown-alert-title\">\u003Csvg class=\"octicon octicon-info mr-2\" viewBox=\"0 0 16 16\" version=\"1.1\" width=\"16\" height=\"16\" aria-hidden=\"true\">\u003Cpath d=\"M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8Zm8-6.5a6.5 6.5 0 1 0 0 13 6.5 6.5 0 0 0 0-13ZM6.5 7.75A.75.75 0 0 1 7.25 7h1a.75.75 0 0 1 .75.75v2.75h.25a.75.75 0 0 1 0 1.5h-2a.75.75 0 0 1 0-1.5h.25v-2h-.25a.75.75 0 0 1-.75-.75ZM8 6a1 1 0 1 1 0-2 1 1 0 0 1 0 2Z\">\u003C\u002Fpath>\u003C\u002Fsvg>Note\u003C\u002Fp>\u003Cp>Free endpoints like \u003Ccode>GET \u002Fv2\u002Fusage\u003C\u002Fcode> are always accessible, regardless of permissions.\u003C\u002Fp>\n\u003C\u002Fdiv>\n\u003Cp>If a key tries to call an endpoint outside its scopes, the API returns a \u003Ccode>403\u003C\u002Fcode> status code.\u003C\u002Fp>\n\u003Ch2 id=\"3-set-rate-limits-optional\">3. Set rate limits (optional)\u003C\u002Fh2>\n\u003Cp>Per-key rate limits let you protect your workspace budget by capping individual integrations:\u003C\u002Fp>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Setting\u003C\u002Fth>\n\u003Cth>Description\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>RPM limit\u003C\u002Ftd>\n\u003Ctd>Maximum requests per minute for this key\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Daily limit\u003C\u002Ftd>\n\u003Ctd>Maximum requests per day for this key\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003Cp>If you don’t set any, your workspace defaults apply automatically. Per-key limits can only cap usage below the workspace maximum. They can never exceed it.\u003C\u002Fp>\n\u003Cp>When a per-key limit is reached, the API returns \u003Ccode>429 Too Many Requests\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch2 id=\"4-add-an-expiration-date-optional\">4. Add an expiration date (optional)\u003C\u002Fh2>\n\u003Cp>Useful for temporary access: contractor keys, demo integrations, or test environments. After the date you choose, the key stops working automatically.\u003C\u002Fp>\n\u003Cp>You can change or remove the expiration anytime by editing the key.\u003C\u002Fp>\n\u003Ch2 id=\"manage-existing-keys\">Manage existing keys\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>Edit.\u003C\u002Fstrong> Click the edit icon on any active key to update its name, permissions, rate limits, or expiration. Changes take effect immediately.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Revoke.\u003C\u002Fstrong> Revoked keys stop working immediately. They stay visible in the table for reference, but cannot be reactivated. When in doubt, create a new key first, update your integration, then revoke the old one.\u003C\u002Fp>\n\u003Ch2 id=\"quick-tips\">Quick tips\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>One key per environment.\u003C\u002Fstrong> Separate keys for dev, staging, and production keep things clean.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Name keys clearly.\u003C\u002Fstrong> A name like \u003Ccode>prod-crm-sync\u003C\u002Fcode> or \u003Ccode>staging-enrichment\u003C\u002Fcode> makes auditing easy.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Scope when you need to.\u003C\u002Fstrong> Start with full access. Restrict later as your team and integrations grow.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2 id=\"something-not-working\">Something not working?\u003C\u002Fh2>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Symptom\u003C\u002Fth>\n\u003Cth>Fix\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>\u003Ccode>403 Forbidden\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>The key is missing a required permission. Edit it in \u003Ca href=\"\u002Fapi-keys\" target=\"_blank\" rel=\"noopener\">API Keys\u003C\u002Fa>\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Ccode>429 Too Many Requests\u003C\u002Fcode>\u003C\u002Ftd>\n\u003Ctd>A per-key rate limit was reached. Raise it or wait for the reset\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>\u003Ccode>401 Unauthorized\u003C\u002Fcode> (expired key)\u003C\u002Ftd>\n\u003Ctd>The key passed its expiration date. Create a new one\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\n\u003C\u002Ftable>\n\u003Cp>For all error codes and retry strategies, see \u003Ca href=\"\u002Fdocs\u002Fguides\u002Ferrors-retries\">Error handling &amp; retries\u003C\u002Fa>.\u003C\u002Fp>\n","","Your keys work out of the box with full access and no configuration needed. This guide covers optional features you can use as your integration grows. [!TIP] Don't have an API k...",3,[20,24,27,30,33,36,39],{"id":21,"title":22,"level":23},"1-create-a-key","1. Create a key",2,{"id":25,"title":26,"level":23},"2-fine-tune-permissions-optional","2. Fine-tune permissions (optional)",{"id":28,"title":29,"level":23},"3-set-rate-limits-optional","3. Set rate limits (optional)",{"id":31,"title":32,"level":23},"4-add-an-expiration-date-optional","4. Add an expiration date (optional)",{"id":34,"title":35,"level":23},"manage-existing-keys","Manage existing keys",{"id":37,"title":38,"level":23},"quick-tips","Quick tips",{"id":40,"title":41,"level":23},"something-not-working","Something not working?",[],[44,45,46],"\u002Fdocs\u002Fguides\u002Fproduction-checklist","\u002Fdocs\u002Fauthentication","\u002Fdocs\u002Fguides\u002Frate-limits-credits",1785860236592]