Partner & Developer onboarding
API credentials
The credential types a subscription can hold in your API Portal, API key, Client ID and Secret, and Private Key JWT, how developers create them and get a first access token, and the difference between Regenerate and Rotate Secret.
A subscription in your API Portal holds its own credentials. The credential type comes from the plan's security level: an API key, a Client ID and Client Secret, or Private Key JWT. A developer creates and manages them on the subscription's Details tab, in the authorization section.
What credential types can a subscription use?
The plan's security level sets the credential type. A subscription receives one of the types below. The plan, not the developer, chooses it.
| Credential type | What the developer gets | How they authenticate |
|---|---|---|
| API key | An API key, and on some gateways a secondary key. | The key is sent with each request. |
| Client ID and Client Secret | An OAuth2 Client ID and Client Secret. | The developer exchanges them for an access token with the client credentials grant. |
| Private Key JWT | A Client ID and a token endpoint, with no secret. | The developer signs a JWT with their private key. The public key is hosted at a JWKS URL. |
Two further types exist for specific gateways: an intermediate server-to-server JWT and an advanced code flow. The plan's security level determines which one applies.
How does a developer get credentials?
When a subscription is Active and has no credentials yet, the developer clicks Create Authorization and confirms. The portal generates the credential and shows it in full once, with a warning to save it.
- The developer opens the subscription and finds the authorization section on the Details tab.
- They click Create Authorization and confirm. The portal generates the credential.
- The portal shows Credentials created successfully! with the full values and the warning to save them now.
- They copy and store the values, then click I've saved my credentials, continue. Leaving the page first asks them to confirm.
- From then on, the portal shows only a masked value. The full key or secret can't be shown again.
Creating, regenerating, and rotating credentials need Full API keys access in the team. Members with Read Only API keys access can see the masked credentials. See Teams.
How does a developer get a first access token?
For a Client ID and Client Secret, the panel with the new credentials has a Generate Access Token section. Generate Token requests an access token through your API Portal and shows it with a copy button.
The button works only while the new secret is on screen, because the portal never shows the secret in full again. Afterwards, the developer requests tokens from your token endpoint with the Client ID and the secret they saved. When the credential carries one, Show example displays a sample request.
What is the difference between Regenerate and Rotate Secret?
Regenerate replaces the whole credential: it revokes the current one and issues a new one, so an OAuth2 client gets a new Client ID and secret. Rotate Secret keeps the Client ID and issues only a new secret. With either action, the old secret stops working at once.
| Action | What it changes | What stays | When it is available |
|---|---|---|---|
| Regenerate Credentials | Revokes the current credential and issues a new one. For OAuth2, a new Client ID and secret. For an API key, a new key. | Nothing of the old credential. | The default, on an Active subscription. |
| Rotate Secret | Issues a new Client Secret. The old secret stops working at once. | The Client ID. | Only on specific custom integrations that Apiable sets up for a gateway. |
The authorization section shows one of the two buttons. With the standard Authorization Servers, Keycloak, Auth0, and Duende, developers always see Regenerate Credentials. See Authorization Servers.
How does Private Key JWT work?
With Private Key JWT there is no client secret. The developer provides a JWKS URL, an HTTPS address where their public signing keys are hosted. The portal registers an OAuth2 client, and the developer authenticates by signing a JWT with the matching private key.
- On a Private Key JWT plan, the subscription starts without a client. The developer enters a JWKS URL and saves it.
- The JWKS URL must use HTTPS. The portal rejects anything else with JWKS URL must use HTTPS.
- The developer clicks Create Authorization. The portal registers a client at your authorization server.
- The authorization section then shows the Client ID, the Token endpoint, the Authentication method, the JWKS URL on file, and the Supported signing algorithms: RS256, ES256, or PS256.
To rotate signing keys, the developer uses Edit JWKS URL and points the client at the new key set. There is no client secret, so a Private Key JWT subscription never offers Rotate Secret.
Private Key JWT registration needs a Keycloak Authorization Server. See Authorization Servers for how Dynamic Client Registration provisions a client per subscription.
When are credentials unavailable or revoked?
Credential availability follows the subscription status and, on a sandbox plan, its pipeline phase. The portal shows a clear state in each case.
| State | What the developer sees |
|---|---|
| Subscription is Pending Approval | Credentials can't be created until your team approves the request. |
| Subscription is Pending Payment | No credential section. A Checkout button on the subscription completes payment, and credentials can be created once it is active. |
| Subscription is Payment Failed | View and pay open invoice on the subscription. Apiable does not revoke credentials when a payment fails. |
| Sandbox plan, not yet in production | A locked Production Credentials card until your team approves the submission. |
| Provisioning failed at the authorization server | Credentials are being provisioned, with a note to contact support or try later. Your team can retry from the subscription's Scopes tab in the dashboard, with Retry Provisioning, when that tab is shown. |
| Subscription is Cancellation Pending | Credentials keep working until the cancellation date. |
| Subscription is Cancelled | "Subscription has been cancelled and all keys have been revoked." |
Where to next
Trying endpoints in the explorer
What the explorer fills in, and where the developer enters the key or secret they saved.
Subscribing to a plan
The subscription wizard and what each subscription status means.
Scope grants
On scope-based plans, approved scopes are added to the existing client, so no new credentials are issued.
From sandbox to production
The sandbox and production credential cards, and when production credentials unlock.