iAdvize
Back

Only Admins can create or revoke API keys

Security

Creating and revoking an organization's API keys (the credential for the public REST API) now requires the Admin role. Previously, any signed-in Member could create or revoke a key; that gap is closed.

Members keep read-only access to the API keys card: they can still see each key's name, obfuscated value, and last-used date, but the New key form and the Revoke button no longer appear for them.

If a Member needs to issue or revoke a key, an Admin has to do it, or promote them first.

See Members for the Admin/Member split, and Authentication for how API keys work.

Updated later

As of 2026-07-16, creating or revoking keys is gated by the API keys: Edit permission, not the Admin role by name. The built-in Admin still holds that permission, but you can now grant it to any custom role too, so "requires the Admin role" above now means "requires anyone with API keys: Edit". Viewing the list needs API keys: View (or Edit). See Roles.

Resources