Create one
1
Open the Admin Keys page
Sign in to the console and pick Build → Admin Keys in the sidebar.
2
Name it and pick scopes
Give it a name you will recognise, such as “reconciliation script”. Then tick only the scopes this script actually needs — the three ticked by default are all read-only. See Scopes.
3
Choose an expiry
7, 30, 90 or 365 days, a custom number of days, or never expires.
4
Save the value immediately
The full value is shown once. After you close the dialog it cannot be viewed again — only its hash is stored.
Authentication
Put the Admin Key in theAuthorization header:
success is false, message carries a readable reason and some errors also include a code.
Hard limits
What an Admin Key can do is entirely determined by the scopes you tick. On top of that there are three boundaries no scope can cross:No admin console
Every admin, agent and supplier endpoint is refused, regardless of the account’s role. An administrator’s Admin Key is still limited to user-side actions.
No account security changes
Password changes, account deletion, two-factor, Passkey, phone and email binding, identity verification — all refused.
No money, no key plaintext
Top-ups, withdrawals, payment methods and invoice submission are refused, and the plaintext of an existing API key can never be retrieved.
Lifecycle
- Limits: at most 10 active Admin Keys per account, and at most 5 created per day.
- Editable: name and scopes can be changed after creation. Expiry cannot — create a new key to change it.
- Revocable: revoke one key, or all of them at once. Revocation is immediate and irreversible.
- A password change kills them all: changing your account password immediately invalidates every Admin Key you own, including ones set to never expire.
If you suspect a leak
1
Revoke immediately
Use “Revoke all” on the Admin Keys page. It also signs you out on every other device.
2
Check the audit log
Open Build → Audit Log to see when the key was first used and from which IP addresses.
3
Create a fresh one
Recreate it with narrower scopes and a shorter expiry, ticking only what the script really uses.
The system records an audit entry when a key repeatedly hits its boundary. Sustained refusals usually mean one of two things: the script is configured with the wrong scopes, or the key is in the hands of someone who does not know its limits.