API keys — giving a client program access to the public API
An API key lets a client program (a store or ERP) read and change company data through the public API. Only a company administrator can create and disable it.
Why use an API key
An API key gives access to a program that is not part of Noxti — a client’s store, ERP, or wholesaler. The program connects to the public API (https://api.noxti.com/v1, described on the API documentation page linked in the tab header) and can do only what the role you select for the key permits. An API key can never receive the company administrator role.
This differs from a technical account for n8n or WAPRO on the Program access (API) tab (technical accounts — ask the company administrator for help): an API key works only with the public API and has its own role. The public API is a paid add-on to the plan.
Where and who
Settings → System → API keys. Only the company administrator can see the tab (Company administrator and superadministrator — who bypasses what). Creating or changing a key, issuing a new secret, revoking a secret, and disabling a key all require fresh 2FA confirmation (Two-factor authentication (2FA) — enabling it, backup codes, and disabling it).
Above the table is the Active keys: X of Y counter. Each key has a row with its name, environment (Production or Test), role, secret prefix, last use, and status.
| Status | Meaning |
|---|---|
| Working | The key is ready and the program can use it to connect. |
| Disabled | The key was permanently disabled; it remains on the list for reference. |
| Different environment | The key was created while the company was in Test mode (or vice versa), so it will not work now — disable it and create a new one. |
| No secret | All secrets for this key have been revoked — use New secret. |
| Not working — add-on missing | The company no longer has the public API add-on. |
New key
- Click New key.
- Name — use it to identify the program using the key (“B2B store,” “Client ERP”). Two active keys cannot have the same name. You cannot change the name later.
- Role — the key can do only what this role permits. It is best to create a separate role for the program with only the permissions it needs (Creating and editing a role — the two-tab window).
- Allowed IP addresses (optional) — if you enter addresses, the key works only from those addresses. Enter one address or a range, up to 50 entries. A pasted list separated by spaces or commas is automatically split into entries. An empty field means the key works from any address.
- Create key — the key secret appears once only. Copy it and give it to the client program before closing the dialog; the dialog will not close until you confirm that the secret has been saved. Later, only its prefix is visible.
Change a key
⋮ → Edit lets you change the role, allowed IP address list, and the Run automations for changes from this key toggle (whether changes made by the program should trigger automatic actions just like employee changes). Only NOXTI support can view and change the requests-per-minute limits.
If someone later changes the key’s role into a company administrator role, the key retains it (and stops working) until you select a different role.
New secret
A secret has an expiry date, just like technical-account tokens. Before it expires, a reminder with a link to this tab goes to the people selected for reminders on the Program access (API) tab (technical accounts — ask the company administrator for help). If nobody is selected there, nobody receives it. ⋮ → New secret issues a new secret (again, shown only once). The old secret continues to work for a short time, giving you time to enter the new one in the program; the expanded row marks it Old, expires. Set how many hours the old secret works in Old key lifetime after rotation (hours) on the Program access (API) tab — the same setting used for technical-account tokens.
Use the same button when:
- you lost the secret — issue a new one, then revoke the old one (below);
- the key has the No secret status.
Do not issue another new secret before the program has switched to the latest one — the previous secret will then stop working immediately.
Revoke a secret (leak)
Expand the key’s row with the arrow on the left to see Secrets for this key — the prefix, creation date, last use, and expiry. Click Revoke next to a secret. The program using it immediately gets an error; other secrets for the key continue to work. Use this to stop a leaked secret or an old secret before the end of its grace period.
Disable a key
Use ⋮ → Disable key when a client stops using the API or the key is no longer needed.
- The client program immediately gets a 401 error; all secrets for the key stop working.
- This cannot be undone. The key remains on the list as disabled, but cannot be re-enabled — create a new one if needed.
- A disabled key frees a place under the limit, and its name becomes available again.
Key limit
The company can have as many active keys as its plan allows (see the counter above the table). Disabled keys do not count. When the limit is full, New key is greyed out — disable a key nobody uses anymore or ask for a higher limit.
Keys with Different environment status still count toward the limit. Disable them first, then create new ones.
If the company does not have the add-on
Without the public API add-on, the tab shows a yellow box: Your plan does not include the public API. You cannot create new keys, change existing ones, or issue new secrets — client programs cannot connect with them anyway. You can still clean up: review keys, revoke secrets, and disable keys. Contact us to get the public API.
If something does not work
- New key is greyed out — the limit is full or the add-on is missing; hover over the button to see why.
- “An active key with this name already exists.” — choose another name or disable the old key with that name first.
- The program gets a 401 error — the secret was revoked or expired, or the key was disabled; also check whether the program connects from an allowed IP address.
- The program gets a 403 error — the key’s role does not permit the operation. Change the role’s permissions or choose another role for the key.
- I cannot see the tab — you are not the company administrator.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo