> ## Documentation Index
> Fetch the complete documentation index at: https://docs.flowsign.app/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Flowsign is one word with a lowercase s.
> The REST API base URL is https://my.flowsign.app and every endpoint lives under /api/v1.
> When answering API questions, cite the HTTP method and endpoint path.
> API access needs the Enterprise plan and an API key with the API access permission.

# API keys

> Create and revoke the organisation's keys for the Flowsign REST API.

**API keys** is for owners only, and requires the Enterprise plan; on a lower plan the page shows an upgrade prompt instead. Only an owner can create or revoke keys, and the role a key is given must have permission to access the API.

<Frame caption="API keys, listing each key's name, key prefix, what it can do, who issued it and its status.">
  <img src="https://mintcdn.com/doc-a97e5290/PTzM8Xl3JBDj-Kc9/images/guides/settings/api-keys.png?fit=max&auto=format&n=PTzM8Xl3JBDj-Kc9&q=85&s=7a81bda45e34cb34a454c4e9309d7dfd" alt="The API keys settings page listing keys by name, prefix, role, issuer and status" width="2880" height="1800" data-path="images/guides/settings/api-keys.png" />
</Frame>

Manage the organisation's API keys here: create a new key, and revoke ones you no longer use. Four cards summarise them (**Total keys**, **Active**, **Expiring soon** and **Revoked**), and the table lists each key's **Name** (with when it was last used), **Key** prefix, **Can do**, **Issued by** and **Status**. An organisation can hold up to 50 unrevoked keys at a time, and expired keys count until they are revoked; revoke one to make room for another. See the [API reference](/api-reference/authentication) for how to authenticate requests with a key.

## Creating a key

**Create API key** asks for:

* **Name**, for example `Production server`.
* **Can do**, the role the key acts as. The key acts as this role, not as you, and only roles with API access are listed.
* **Workspace**, the one workspace the key works in.
* **Expiry**, optional. Leave it blank for a key that never expires.

Click **Create key**. The key is shown once, in **Save your API key**. Copy it straight away: it can't be retrieved or rotated later, so if you lose it, revoke the key and create a new one.

<Frame caption="Creating an API key.">
  <img src="https://mintcdn.com/doc-a97e5290/PTzM8Xl3JBDj-Kc9/images/guides/settings/api-keys/create-key-dialog.png?fit=max&auto=format&n=PTzM8Xl3JBDj-Kc9&q=85&s=8d4a7a7d6491a92efdf749b8688667ce" alt="The create API key dialog with Name, Can do, Workspace and Expiry fields" width="1080" height="1200" data-path="images/guides/settings/api-keys/create-key-dialog.png" />
</Frame>

## Revoking a key

**Revoke key** stops a key working straight away. This cannot be undone.

## Related

* [API reference](/api-reference/authentication)
* [Webhooks](/guides/settings/webhooks)
* [Integrations](/guides/settings/integrations)
