API keys

Create and scope API keys for server-to-server calls, rotate a leaked key, and see exactly which permissions a key needs.

Last updated

An API key lets a server, script or CI job call your project's REST API without a signed-in user. You send it in the x-api-key header, and Anythink checks it against the permissions you gave it when you created it. Keys are for code you run yourself. Your app's users sign in instead.

How API keys work#

A key belongs to the user who created it and carries a list of permissions you pick at creation time. Three rules follow from that.

  • A key can only hold permissions its creator holds. If you ask for a permission you don't have, the key is created without it. Check the permissions on the key afterwards.
  • A key is checked per endpoint. Each REST endpoint needs a permission such as orders:read. A key without it gets 403 Forbidden.
  • A key acts as its creator for row-level security. Records the creator can't see, the key can't see either. See Groups and row-level security.

Keys look like ak_ followed by a random string. Anythink stores only a hash, so the full key is shown once, when you create it, and can't be retrieved afterwards. If you lose it, create a new one.

Permission names follow the entity:action pattern: orders:read, orders:create, orders:update, orders:delete. Permissions for platform features that aren't tied to one of your entities appear under Anythink Permissions in the dashboard.

Limit: Each key name must be unique among your own keys. You see and manage only the keys you created.

Create a key#

Choose the expiry and permissions deliberately. A key with orders:read and a 30-day expiry that leaks is an annoyance. A key with every permission and a year left is an incident.

In the Anythink dashboard

  1. Open My Account and select the API Keys tab.
  2. Enter a Name that says what uses the key, for example nightly-export.
  3. Choose Expires in (days): 30, 90, 180 or 365. The default is 30.
  4. Under Permissions, select only what the caller needs. Entity permissions are listed under Data Model Permissions, platform permissions under Anythink Permissions.
  5. Select Create API Key.

The new key appears in a yellow banner: Copy your API key now. It will never be shown again! Copy it into your secret store before you leave the page.

With the CLI

bash
anythink api-keys create nightly-export \
  --permissions orders:read,customers:read \
  --expires-in 90 \
  --save-as nightly-export \
  --yes

--permissions is required and takes permission names. --expires-in defaults to 90 days and is capped at 365 unless you add --no-expiry-cap.

With --save-as, the CLI stores the key in a new profile and never prints it. Use it with anythink --profile nightly-export <command>. Without --save-as, the key is written once to stderr, so you can capture it with 2> key.txt or paste it into a secret store.

If the key's creator lacks a permission you asked for, the CLI warns you which permissions were dropped.

With an AI assistant (MCP)

With the local MCP server (anythink-mcp), ask the assistant to create the key and tell it to save it to a profile:

Create an API key called nightly-export with orders:read and customers:read, expiring in 90 days, and save it as the profile nightly-export.

The assistant runs api-keys create through the cli tool. Ask for --save-as so the key goes into a profile and doesn't pass through the conversation.

Note: Create keys in the dashboard or with your local CLI. The dashboard's AI assistant doesn't create keys, so key values never pass through a chat.

Use a key#

Send the key in the x-api-key header on any REST call. Set ORG_ID to your project ID.

bash
curl "https://api.my.anythink.cloud/org/$ORG_ID/entities/orders/items" \
  -H "x-api-key: $ANYTHINK_API_KEY"

Read the key from an environment variable or secret manager. Don't paste it into source files.

A revoked or expired key is refused. A valid key without the endpoint's permission gets 403 Forbidden.

Apply least privilege#

  • Grant the smallest set of permissions that works. A reporting job needs orders:read, not orders:update. Create one key per job so you can revoke one without breaking the others.
  • Use the shortest expiry you can live with. Expiry limits how long a leaked key stays dangerous. Expired keys stop working automatically.
  • Rotate on a schedule. Create the replacement key, deploy it, confirm calls succeed, then revoke the old one. Both work during the overlap, so there's no downtime.
  • Revoke on suspicion. If a key appeared in a log, a commit or a screenshot, revoke it now and create a new one.

Keep keys on the server#

An API key is a credential for your backend. Never put one in browser code, a mobile app, or a repository, because anyone who can read the code can read the key and act with its permissions.

For apps, have users sign in and call the API with their own session, so role permissions and row-level security apply per person. See Anythink SDK and Sign-in.

Revoke a key#

Revoking is immediate and can't be undone. The key stops working and stays in your list marked as revoked.

In the Anythink dashboard

  1. Open My Account and select the API Keys tab.
  2. Find the key in Your API Keys. Select View Permissions first if you want to confirm which key it is.
  3. Select Revoke, then confirm with Revoke in the dialog.

The Status column changes from Active to Revoked.

With the CLI

bash
anythink api-keys list
anythink api-keys revoke 42 --yes

api-keys list shows each key's ID, name, permission count, expiry date and status (active, revoked or expired). Pass the ID to api-keys revoke. Without --yes, the CLI shows the key and asks you to confirm.

With an AI assistant (MCP)

With the local MCP server, ask the assistant:

List my API keys, then revoke the one called nightly-export.

The assistant runs api-keys list, then api-keys revoke <id> --yes. It never sees key values: the list shows only metadata.

Next steps#