---
title: "API keys"
description: "Create, use and revoke API keys, which act as a user or bot with exactly its access."
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.ezghcloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys

An API key is a credential for code. It acts as its owner, a user or a [bot](/iam/bots), with exactly the owner's access. A key has no permissions of its own: its access is checked on every request and changes when its owner's does. To give code less access than you have, create a bot with only the policies it needs, and a key for the bot.

| Property | Value |
| --- | --- |
| Format | `ezgh_` followed by 40 letters and digits |
| Shown | Once, when it's created |
| Identified by | Its name and its first characters, like `ezgh_Ab3dE6…` |
| Expiry | 1 to 365 days after creation, or never |
| Name | 1 to 100 characters |

## Create an API key

You create keys signed in, in the console or the CLI. An API key can't create API keys.

- A key for yourself needs `apiKeys.create`. It's included in `BasicAccess`.
- A key for a bot needs `bots.createApiKey` on the bot. See [Create an API key for a bot](/iam/bots#create-an-api-key-for-a-bot).
- Nobody can create a key for another user.

### Console

1. Open the account menu and select **API keys**. This opens the **API keys** tab of your own user page.
2. Select **Create API key**.
3. Enter a **Name** and choose when it **Expires**: **30 days**, **90 days**, **1 year** or **Never**. The default is 90 days.
4. Review, then select **Create key**.
5. Copy the key. It won't be shown again.
### CLI

```sh
ezgh iam api-keys create laptop --expires-in-days 90
```

The key is printed once, on standard output. Without `--expires-in-days`, the key doesn't expire. Add `--bot <bot>` to create the key for a bot.

## Use an API key

Send the key as a bearer token:

```sh
curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/projects \
  -H "Authorization: Bearer $EZGH_API_KEY"
```

Every EZGH Cloud API accepts API keys the same way. A key that's malformed, revoked or expired, or whose owner has left the organization, gets `401`.

## List API keys

Everyone can see their own keys. Seeing every key in the organization needs `apiKeys.list`. In the console, a user's or bot's keys are on the **API keys** tab of their page, with the date each was **Last used**.

### CLI

```sh
ezgh iam api-keys list
```
### API

```sh
curl https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/api-keys \
  -H "Authorization: Bearer $EZGH_API_KEY"
```

See [ListApiKeys](/orgs-api/apiKeys/ListApiKeys/).

## Revoke an API key

A revoked key stops working immediately. Revoking can't be undone. You can revoke your own keys; revoking anyone else's needs `apiKeys.delete`.

### Console

On the **API keys** tab of the owner's page, select **Revoke** next to the key, then confirm.
### CLI

```sh
ezgh iam api-keys delete laptop
```

The key can be given by ID, name or prefix.
### API

```sh
curl -X DELETE https://orgs.ezghcloud.com/v1/organizations/$ORG_ID/api-keys/$KEY_ID \
  -H "Authorization: Bearer $EZGH_API_KEY"
```

See [DeleteApiKey](/orgs-api/apiKeys/DeleteApiKey/).

Keys are also revoked when:

- their owner is removed from the organization or leaves it;
- their owner is a bot and the bot is deleted;
- their owner is suspended by your identity provider over [SCIM](/iam/scim). Reactivating the user doesn't restore the keys.

Source: https://docs.ezghcloud.com/iam/api-keys/index.mdx
