Apiable

Partner & Developer onboarding

API credentials

The credential types a subscription can hold in your API Portal, API key, Client ID and Secret, and Private Key JWT, how developers create them and get a first access token, and the difference between Regenerate and Rotate Secret.

A subscription in your API Portal holds its own credentials. The credential type comes from the plan's security level: an API key, a Client ID and Client Secret, or Private Key JWT. A developer creates and manages them on the subscription's Details tab, in the authorization section.

What credential types can a subscription use?

The plan's security level sets the credential type. A subscription receives one of the types below. The plan, not the developer, chooses it.

Credential typeWhat the developer getsHow they authenticate
API keyAn API key, and on some gateways a secondary key.The key is sent with each request.
Client ID and Client SecretAn OAuth2 Client ID and Client Secret.The developer exchanges them for an access token with the client credentials grant.
Private Key JWTA Client ID and a token endpoint, with no secret.The developer signs a JWT with their private key. The public key is hosted at a JWKS URL.

Two further types exist for specific gateways: an intermediate server-to-server JWT and an advanced code flow. The plan's security level determines which one applies.

How does a developer get credentials?

When a subscription is Active and has no credentials yet, the developer clicks Create Authorization and confirms. The portal generates the credential and shows it in full once, with a warning to save it.

  1. The developer opens the subscription and finds the authorization section on the Details tab.
  2. They click Create Authorization and confirm. The portal generates the credential.
  3. The portal shows Credentials created successfully! with the full values and the warning to save them now.
  4. They copy and store the values, then click I've saved my credentials, continue. Leaving the page first asks them to confirm.
  5. From then on, the portal shows only a masked value. The full key or secret can't be shown again.

Creating, regenerating, and rotating credentials need Full API keys access in the team. Members with Read Only API keys access can see the masked credentials. See Teams.

How does a developer get a first access token?

For a Client ID and Client Secret, the panel with the new credentials has a Generate Access Token section. Generate Token requests an access token through your API Portal and shows it with a copy button.

The button works only while the new secret is on screen, because the portal never shows the secret in full again. Afterwards, the developer requests tokens from your token endpoint with the Client ID and the secret they saved. When the credential carries one, Show example displays a sample request.

What is the difference between Regenerate and Rotate Secret?

Regenerate replaces the whole credential: it revokes the current one and issues a new one, so an OAuth2 client gets a new Client ID and secret. Rotate Secret keeps the Client ID and issues only a new secret. With either action, the old secret stops working at once.

ActionWhat it changesWhat staysWhen it is available
Regenerate CredentialsRevokes the current credential and issues a new one. For OAuth2, a new Client ID and secret. For an API key, a new key.Nothing of the old credential.The default, on an Active subscription.
Rotate SecretIssues a new Client Secret. The old secret stops working at once.The Client ID.Only on specific custom integrations that Apiable sets up for a gateway.

The authorization section shows one of the two buttons. With the standard Authorization Servers, Keycloak, Auth0, and Duende, developers always see Regenerate Credentials. See Authorization Servers.

How does Private Key JWT work?

With Private Key JWT there is no client secret. The developer provides a JWKS URL, an HTTPS address where their public signing keys are hosted. The portal registers an OAuth2 client, and the developer authenticates by signing a JWT with the matching private key.

  1. On a Private Key JWT plan, the subscription starts without a client. The developer enters a JWKS URL and saves it.
  2. The JWKS URL must use HTTPS. The portal rejects anything else with JWKS URL must use HTTPS.
  3. The developer clicks Create Authorization. The portal registers a client at your authorization server.
  4. The authorization section then shows the Client ID, the Token endpoint, the Authentication method, the JWKS URL on file, and the Supported signing algorithms: RS256, ES256, or PS256.

To rotate signing keys, the developer uses Edit JWKS URL and points the client at the new key set. There is no client secret, so a Private Key JWT subscription never offers Rotate Secret.

Private Key JWT registration needs a Keycloak Authorization Server. See Authorization Servers for how Dynamic Client Registration provisions a client per subscription.

When are credentials unavailable or revoked?

Credential availability follows the subscription status and, on a sandbox plan, its pipeline phase. The portal shows a clear state in each case.

StateWhat the developer sees
Subscription is Pending ApprovalCredentials can't be created until your team approves the request.
Subscription is Pending PaymentNo credential section. A Checkout button on the subscription completes payment, and credentials can be created once it is active.
Subscription is Payment FailedView and pay open invoice on the subscription. Apiable does not revoke credentials when a payment fails.
Sandbox plan, not yet in productionA locked Production Credentials card until your team approves the submission.
Provisioning failed at the authorization serverCredentials are being provisioned, with a note to contact support or try later. Your team can retry from the subscription's Scopes tab in the dashboard, with Retry Provisioning, when that tab is shown.
Subscription is Cancellation PendingCredentials keep working until the cancellation date.
Subscription is Cancelled"Subscription has been cancelled and all keys have been revoked."

Where to next