API keys
For portal owners. Only where the portal has API keys.
An API key lets an external system make requests to a Cloud site without a person signing in. Anything holding a valid key has the access that key was issued with, so treat a key like a password.
A user needs the API Key management permission for the site to view and work with API keys.
Generate a key
- Open the API Keys tab.
- Select Add new key.
- Give the key a name, a description and an expiry time.
- Copy the key and store it somewhere safe.
Warning
The key value is shown only once, at the point you create it. Cloud cannot show it again. If you lose a key, delete it and generate a replacement.
Delete a key
- Select the API key.
- Choose Delete in the toolbar.
- Follow the prompt to confirm the deletion.
This cannot be undone.
Edit a key
- Select the API key.
- Choose Edit in the toolbar.
- Edit the key's name and description, or toggle its suspension state.
Manage key permissions
Set the scope of a key by selecting it in the permissions section of the tab. By default a key is granted all of the site and device permissions available to API keys. These permissions map to the same permissions a user holds.
API key notes
Each API key is rate limited three ways at once, and the first limit reached is the one that stops the request.
| Limit | Applies to |
|---|---|
| 300 requests per minute | Everything the key does, added together |
| 4 requests every 4 seconds | Any single endpoint |
| 1 request every 2 seconds | The device data endpoint |
The per-endpoint limit is the one an integrator meets first: an application polling one endpoint hits 4 requests every 4 seconds long before it gets near 300 a minute. If an application is hitting a limit, ask your portal owner.
Full documentation for the Cloud API is published separately.