Guides

Connect integrations with an API key

An API key lets a script or tool call ExpiryEdge without anyone's password. It belongs to your organization, so it keeps working when people leave.

Before you start

  • Creating, listing and revoking keys needs the admin role.
  • Each key is Editor (read and change, the default) or Viewer (read-only). A key can never do admin tasks (users, billing, organization settings, API keys) or personal-account actions.
  • Up to 25 active keys per organization. Use one key per integration.
  • Anyone with the key can use it. Treat it like a password.
export BASE="https://api.expiryedge.com/v1"

Step 1: Create a key

In the app: go to Settings > API keys, click Create API key, enter a name (e.g. "Nightly HR import"), choose Editor or Viewer, and click Create API key. Copy the key - it is shown once. A lost key can't be recovered; revoke it and create a new one.

With the API (admin session token, see Authentication):

curl -s -X POST "$BASE/createApiKey" \
  -H "Authorization: Bearer $ADMIN_TOKEN" -H "Content-Type: application/json" \
  -d '{"name":"Nightly HR import","role":"editor"}'
{
  "key": "ee_live_4fQ9vB2kLm8XzT1rW6yNp0sHc3dJ5gA7uE9iO2qR4tY",
  "api_key": { "id": "k7Qm2xKpA1", "prefix": "ee_live_4fQ9", "role": "editor", "status": "active", "expires_at": null, ... }
}

Optional: "expires_at":"2027-01-01T00:00:00Z" makes the key stop working at that time.

Step 2: Use the key

export API_KEY="ee_live_..."
curl -s "$BASE/getPaginatedExpiries?page=1&limit=5" -H "Authorization: Bearer $API_KEY"

If your tool only supports custom headers, send X-API-Key: $API_KEY instead.

In the app, records the key creates or changes show "API key: Nightly HR import" as the author. Keys don't appear in your team list or use a seat.

Step 3: See your keys

curl -s "$BASE/getApiKeys" -H "Authorization: Bearer $ADMIN_TOKEN"
{ "api_keys": [ { "id": "k7Qm2xKpA1", "name": "Nightly HR import", "prefix": "ee_live_4fQ9", "status": "active", "last_used_at": "2026-09-27T22:00:04.000Z", ... } ] }
  • Only the first 12 characters (prefix) are shown, never the full key.
  • last_used_at updates at most once a minute.
  • status is active, expired or revoked.

Step 4: Revoke a key

In the app, click the bin icon next to the key. With the API:

curl -s -X POST "$BASE/revokeApiKey" \
  -H "Authorization: Bearer $ADMIN_TOKEN" -H "Content-Type: application/json" \
  -d '{"id":"k7Qm2xKpA1"}'

The key stops working immediately and can't be turned back on. Records it created stay.

Common problems

SymptomFix
401Key is wrong, revoked or expired. Check you copied all of it (starts with ee_live_), or create a new one.
403 on a writeThe key is Viewer. Create an Editor key.
403 on users, billing, settings or keysKeys can't do admin tasks. Use the app or an admin's session token.
404 for an ID you know existsThe record is in another organization.
409 LIMIT_REACHED25 active keys already. Revoke unused ones.
400 VALIDATION_FAILEDName missing or over 100 characters, role not editor/viewer, or expires_at not in the future.
Retried create returned "key": nullIdempotent replay - the key is never stored. Revoke it and create a new one.

Reference

  • POST createApiKey - create a key (admin). The full key is only in this response.
  • GET getApiKeys - list keys, newest first (admin).
  • POST revokeApiKey - revoke a key (admin).
  • Use: Authorization: Bearer ee_live_... or X-API-Key: ee_live_....

Full details: openapi.yaml.