Create and manage API keys

How-to guide4 min read

An API key proves a request comes from your account. Every request sends it in the Authorization header. You manage keys on the Developers page.

Create a key

  1. Open Developers, then API keys

    Choose Test mode or Live mode at the top right. Keys belong to one mode.

  2. Select Create key and give it a name

    Name it after where it will run, such as Production server. Optionally set an expiry date or limit it to your server's IP addresses.

  3. Confirm it’s you (live keys only)

    Enter your password. If you sign in with Google, Apple or Microsoft, enter the 6-digit code we email you.

  4. Copy the key and store it

    The key is shown once. Notriv keeps only a fingerprint of it, so it can't be shown again. Tick I've saved this key to close.

Important
Live keys can only be created on accounts with a plan or purchased signatures. Test keys are always free.

Store it safely

Put the key in an environment variable or secrets manager on your server and read it from there:

const notriv = new Notriv(process.env.NOTRIV_SECRET_KEY)
Caution
Never put a secret key in browser code, a mobile app, a URL or a Git repository. Anyone who has it can send documents from your account. A key sent in a URL is refused.

Key options

OptionWhat it does
Expires afterThe key stops working after 30 days, 90 days or 1 year. Leave as Never for long-running servers.
Only allow these IPsRequests from any other address get 403 ip_not_allowed. Use your servers’ fixed outbound IPs.

Roll a key

Rolling replaces a key without downtime. Select Roll: you get a new key, and the old one keeps working for 24 hours so you can update your servers. Roll a key whenever someone who had it leaves, or if it might have been exposed.

Revoke a key

Select Revoke. The key stops working immediately and can't be restored.

Security alerts

  • The account owner is emailed whenever a live key is created, rolled or revoked.
  • Each key shows when and from which IP address it was last used.
  • Every key change is recorded in your account's audit log.

Next steps

Was this page helpful?