Skip to main content

API keys

Create and manage the keys other systems use to reach your Cloneable data.

Written by Ryan Miller

An API key lets another system talk to Cloneable on your behalf, without a person signing in. Cloneable's own description:

On screen: "API keys are used to authenticate requests into the Cloneable Platform."

If you integrate Cloneable with something your team has built, you need one.


Ask us for one

Issuing and revoking keys is something we do for you today. Tell us what you connect and we will set it up and hand the key over safely.

We issue every key with an expiry date. Ask us for that date when we hand over the key and make a note of it: when it passes, the key stops working, and anything using it stops with it.


The one thing you must get right

We show a key once, at the moment we create it, and never again.

That is deliberate and it is the correct behavior, but it means the moment of handover is the only chance. Put it wherever your team keeps credentials before you do anything else, and do not rely on being able to come back for it. Nothing anywhere in Cloneable will show you the value a second time.


Do not send it back to us

Once you have a key, do not paste it into an email, a chat message or a support ticket, including to us. If we need to check something about a key we will ask you to identify it another way.

The same rule applies to credentials you store in Cloneable for your integrations. See Store the credentials your integrations need.


Keys cannot be given names

There is no way to label a key, so a list of them will not tell you which is which. If you will have more than one, keep your own note of what each was issued for and when.

That record is what makes it possible to revoke the right one later without breaking something else.


Revoking one

Revoking is immediate, and you cannot undo it. Anything using that key stops working straight away.

So before asking us to revoke, be sure you know what depends on it. If a key has been exposed, revoke it anyway and deal with the breakage: an exposed key is the worse problem.


If an integration stops working

Two likely causes, in the order worth checking:

  1. The key expired. Every key has an expiry date, so check whether the date we gave you at handover has passed.

  2. The key was revoked, perhaps at the request of somebody else on your team.

Tell us which integration stopped and roughly when, and we can tell you which of those it was.


Did this answer your question?