API keys — give a client’s program access to the public API
An API key lets a client’s program (store, ERP) read and change company data through the public API. Only a company administrator can create or disable one.
What an API key is for
An API key gives access to a program that is not part of Noxti — a customer’s store, ERP, or wholesaler. The program connects to the public API (https://api.noxti.com/v1, described on the API documentation page linked in the tab header) and can do only what the role selected for the key allows. A key can never be assigned the company administrator role.
This is different from a technical account for n8n or WAPRO on the Programmatic access (API) tab (technical accounts — see the company administrator’s guide): an API key works only with the public API and has its own role. The public API is a paid add-on to your package.
Where and who
Settings → System → API keys. Only the company administrator can see this tab (Unternehmensadministrator und Superadministrator – wer welche Prüfungen umgeht). Creating or changing a key, issuing a new secret, revoking a secret, or disabling a key requires fresh 2FA confirmation (Zwei-Faktor-Authentifizierung (2FA) – aktivieren, Wiederherstellungscodes, deaktivieren).
Above the table is the Active keys: X of Y counter. Each key has a row showing its name, environment (Production or Test), role, secret prefix, last use, and status.
| Status | Meaning |
|---|---|
| Working | The key is ready; a program can connect with it. |
| Disabled | The key has been permanently disabled; it remains in the list for reference. |
| Different environment | The key was created while the company was in the Test environment (or vice versa) and will not work now; disable it and create a new one. |
| No secret | All secrets for the key have been revoked; use New secret. |
| Not working — missing module | The company no longer has the public API add-on. |
New key
- Click New key.
- Name — use it to identify which program uses the key (for example, “B2B store” or “Client ERP”). Two active keys cannot have the same name. You cannot change the name later.
- Role — the key can do only what this role allows. It is best to create a separate role for the program with only the permissions it needs (Rolle erstellen und bearbeiten – Dialog mit zwei Registerkarten).
- Allowed IP addresses (optional) — if you enter addresses, the key works only from those addresses. You can enter one address or a range, up to 50 entries. A pasted list separated by spaces or commas is automatically split into entries. Leave it blank to allow the key from any address.
- Click Create key. The key secret appears once only. Copy it and pass it to the client’s program before closing the dialog; it will not close until you confirm that the secret is saved. Afterwards, only its prefix is visible.
Change a key
⋮ → Edit lets you change the role, IP address list, and the Run automations for changes from this key switch (whether changes made by the program should trigger automated actions just like employee changes). Only Noxti support can see and change requests-per-minute limits.
If someone later changes the key’s role to the company administrator role, the key keeps that role (and stops working) until you select another role.
New secret
A secret has an expiry date, like technical-account tokens. Before it expires, people selected for reminders on the Programmatic access (API) tab (technical accounts — see the company administrator’s guide) get a reminder with a link to this tab; if no one is listed there, no one gets it. ⋮ → New secret issues a new secret (again, shown once only). The old secret continues to work for a short time, giving you time to enter the new one in the program; it is marked Old, expiring in the expanded row. Set the old secret’s remaining lifetime in hours on the Programmatic access (API) tab, under How long the old key works after rotation (hours) — the same setting used for technical-account tokens.
Use the same button if:
- you lost the secret — issue a new one and revoke the old one (below);
- the key has No secret status.
Do not issue another new secret until the program has switched to the latest one; doing so immediately disables the previous secret.
Revoke a secret (leak)
Expand the key’s row using the arrow on the left to see Secrets for this key — each secret’s prefix, creation date, last use, and expiry. Click Revoke beside a secret. The program using it immediately gets an error; the key’s other secrets continue working. Use this to stop a leaked secret or an old secret before its transition period ends.
Disable a key
Use ⋮ → Disable key when the client stops using the API or the key is no longer needed.
- The client’s program immediately gets a 401 error; all secrets for the key stop working.
- This cannot be undone. The disabled key remains in the list, but cannot be re-enabled; create a new one if needed.
- A disabled key frees a slot under your limit, and its name becomes available again.
Key limit
A company can have as many active keys as its package allows (shown above the table). Disabled keys do not count. When the limit is full, New key is disabled; disable a key no one uses or ask for a higher limit.
Keys with Different environment status still count towards the limit. Disable them first, then create new ones.
If the company does not have the add-on
Without the public API add-on, the tab shows a yellow box: Your package does not include the public API. You cannot create new keys, change existing ones, or issue new secrets; client programs cannot connect with them anyway. You can still clean up: review keys, revoke secrets, and disable keys. Contact us to get the public API.
If something does not work
- New key is disabled — the limit is full or the add-on is missing; hover over the button to see why.
- “An active key with this name already exists.” — choose another name or disable the old key with that name first.
- The program gets a 401 error — the secret was revoked or expired, or the key was disabled. Also check that the program connects from an allowed IP address.
- The program gets a 403 error — the key’s role does not allow this operation. Change the role’s permissions or assign a different role to the key.
- I cannot see the tab — you are not a company administrator.
Möchtest du NOXTI mit deinen Bestellungen kennenlernen? Wir zeigen dir NOXTI mit deinen Vertriebskanälen und deinem Lager.
Präsentation vereinbaren