API Key Management
API keys provide programmatic access to the Neuramancer API. This guide covers API key management, rotation strategies, and best practices for maintaining secure, uninterrupted access to the API.
Overview
Section titled “Overview”API keys are managed through dedicated endpoints at /v1/auth/api. Each tenant can have multiple API keys with different expiration dates, enabling sophisticated rotation strategies.
- Multiple keys per tenant: Support overlapping keys for zero-downtime rotation
- Mandatory expiration dates: All keys must have future expiry dates
- One-time secret visibility: Secrets shown only during creation
- UUID-based deletion: Delete keys by their unique identifier
Best Practices
Section titled “Best Practices”- Regularly rotate API keys using overlapping expiration dates
- Use descriptive names for each key (e.g., “Production”, “Staging”, “CI/CD”)
- Set expiration dates to enforce key rotation
Viewing API Keys
Section titled “Viewing API Keys”Retrieve all API keys for your tenant. The response never includes secret values - only metadata.
Endpoint: GET /v1/auth/api?tenantName=<tenant_name>
Creating API Keys
Section titled “Creating API Keys”Create a new API key for your tenant using POST /v1/auth/api. The secret is returned only once in the response.
Endpoint: POST /v1/auth/api
Response: 201 Created
Deleting API Keys
Section titled “Deleting API Keys”Delete an API key by its UUID.
Endpoint: DELETE /v1/auth/api?tenantName=<tenant_name>&uuid=<uuid>
Security Best Practices
Section titled “Security Best Practices”Expiration Policies
Section titled “Expiration Policies”Set expiration dates based on environment:
- Production: 3-6 months
- Test: Up to 12 months
Storage and Distribution
Section titled “Storage and Distribution”- Use secrets managers: AWS Secrets Manager, HashiCorp Vault, Azure Key Vault
- Never commit to version control: Add to
.gitignore - Encrypt at rest: Use encrypted environment variables
- Limit access: Only authorized personnel/systems
- Audit access: Log who retrieves keys and when
Compromise Response
Section titled “Compromise Response”If an API key is compromised:
- Inform us immediately at [email protected]
- Immediately deactivate the compromised key
- Create a new key with different expiration
- Update all systems to use new key
- Audit usage logs for unauthorized access
- Document incident for security review
- Delete compromised key after migration
Least Privilege
Section titled “Least Privilege”- Limit key distribution to necessary systems only
- Consider using different tenants for isolated environments
- Monitor usage patterns for anomalies
Troubleshooting
Section titled “Troubleshooting”Can’t View Key Secret
Section titled “Can’t View Key Secret”Cause: This is by design. Secrets are only visible on first retrieval.
Solution: Create a new key - there’s no way to view a masked secret again.
