Skip to content

Managing keys

Keys are created, edited, rotated and revoked from the Self-Managed Integration page. Nothing here can be done by an API call.

A key is shown exactly once

The full key appears immediately after it is created or rotated, and never again — only a hash of it is stored, so no endpoint can return it and no one at Localoy can look it up. Copy it into your configuration while it is on screen. If you lose it, rotate the key and take the new one.

Rotate

Same key row, new secret.

Rotation keeps the key's name, scopes and history and replaces only the secret. There is no grace period — the previous secret stops working the moment the new one is issued, because the usual reason to rotate is that the old one leaked. Have the new value ready to deploy before you press the button. If an integration must not go down, create a second key, deploy it, then revoke the first.

Revoke

Immediate, final, and kept on the record.

A revoked key stops authenticating at once. The row stays in your list rather than disappearing, so which key existed, what it could reach and when it was withdrawn remain answerable — but it cannot be brought back, and a revoked key cannot be edited or rotated. Revoked keys do not count towards your active-key limit.

Expiry and limits

Up to 20 active keys per business.

A key can be given an expiry date, after which it stops authenticating on its own — useful for a contractor's key or a one-off migration. Leave it blank for a key that never expires. An expired key answers the same 401 as any other invalid credential, so if an integration stops working on a date you once chose, check the key's expiry before anything else.

Keeping a key safe

The short version of every credential guide, written for this key.

  • Keep it on your server. A key in browser JavaScript, a mobile app binary or a public repository is a key anyone can read and use as you.
  • Give each system its own key, scoped to what that system does. A POS that only pushes stock does not need the scope that deletes items.
  • Use a Sandbox key while you build. It is visibly different from a live one, so a test credential in production configuration is caught on sight.
  • Rotate on any suspicion, and revoke the moment a system is decommissioned — a key nobody is using is still standing authorisation.
  • Log the key prefix, never the key. The prefix is safe to write down and is enough for Localoy to identify which credential a request used.