Connect integrations with an API key
An API key lets a script or tool call ExpiryEdge without anyone's password. It belongs to your organization, so it keeps working when people leave.
Before you start
- Creating, listing and revoking keys needs the admin role.
- Each key is Editor (read and change, the default) or Viewer (read-only). A key can never do admin tasks (users, billing, organization settings, API keys) or personal-account actions.
- Up to 25 active keys per organization. Use one key per integration.
- Anyone with the key can use it. Treat it like a password.
export BASE="https://api.expiryedge.com/v1"Step 1: Create a key
In the app: go to Settings > API keys, click Create API key, enter a name (e.g. "Nightly HR import"), choose Editor or Viewer, and click Create API key. Copy the key - it is shown once. A lost key can't be recovered; revoke it and create a new one.
With the API (admin session token, see Authentication):
curl -s -X POST "$BASE/createApiKey" \
-H "Authorization: Bearer $ADMIN_TOKEN" -H "Content-Type: application/json" \
-d '{"name":"Nightly HR import","role":"editor"}'{
"key": "ee_live_4fQ9vB2kLm8XzT1rW6yNp0sHc3dJ5gA7uE9iO2qR4tY",
"api_key": { "id": "k7Qm2xKpA1", "prefix": "ee_live_4fQ9", "role": "editor", "status": "active", "expires_at": null, ... }
}Optional: "expires_at":"2027-01-01T00:00:00Z" makes the key stop working at that time.
Step 2: Use the key
export API_KEY="ee_live_..."
curl -s "$BASE/getPaginatedExpiries?page=1&limit=5" -H "Authorization: Bearer $API_KEY"If your tool only supports custom headers, send X-API-Key: $API_KEY instead.
In the app, records the key creates or changes show "API key: Nightly HR import" as the author. Keys don't appear in your team list or use a seat.
Step 3: See your keys
curl -s "$BASE/getApiKeys" -H "Authorization: Bearer $ADMIN_TOKEN"{ "api_keys": [ { "id": "k7Qm2xKpA1", "name": "Nightly HR import", "prefix": "ee_live_4fQ9", "status": "active", "last_used_at": "2026-09-27T22:00:04.000Z", ... } ] }- Only the first 12 characters (
prefix) are shown, never the full key. last_used_atupdates at most once a minute.statusisactive,expiredorrevoked.
Step 4: Revoke a key
In the app, click the bin icon next to the key. With the API:
curl -s -X POST "$BASE/revokeApiKey" \
-H "Authorization: Bearer $ADMIN_TOKEN" -H "Content-Type: application/json" \
-d '{"id":"k7Qm2xKpA1"}'The key stops working immediately and can't be turned back on. Records it created stay.
Common problems
| Symptom | Fix |
|---|---|
| 401 | Key is wrong, revoked or expired. Check you copied all of it (starts with ee_live_), or create a new one. |
403 on a write | The key is Viewer. Create an Editor key. |
403 on users, billing, settings or keys | Keys can't do admin tasks. Use the app or an admin's session token. |
404 for an ID you know exists | The record is in another organization. |
409 LIMIT_REACHED | 25 active keys already. Revoke unused ones. |
400 VALIDATION_FAILED | Name missing or over 100 characters, role not editor/viewer, or expires_at not in the future. |
Retried create returned "key": null | Idempotent replay - the key is never stored. Revoke it and create a new one. |
Reference
POST createApiKey- create a key (admin). The full key is only in this response.GET getApiKeys- list keys, newest first (admin).POST revokeApiKey- revoke a key (admin).- Use:
Authorization: Bearer ee_live_...orX-API-Key: ee_live_....
Full details: openapi.yaml.
