Secrets Management

Goal: Securely manage API keys and credentials.


API Key Management

Creating an API Key

Option A: Using the UI

  1. Open the APIs menu in the AppFrameBar
  2. Select API Keys
  3. Choose an expiration preset (15min, 1h, 8h, 24h, 7d, or 30d)
  4. Click Generate JWT
  5. Copy the token immediately - it won't be shown again
API key management interface

Option B: Ask Azi

Thinking Tip:

Copy your API key immediately. It won't be shown again for security reasons.


JWT Tokens

Token Generation

  1. Open APIs menu → API Keys
  2. Select an expiration preset:
    • 15 minutes - CLI smoke tests
    • 1 hour - Short automation
    • 8 hours - Full workday
    • 24 hours - Daily rotation
    • 7 days - Temporary integration
    • 30 days - Long-lived service
  3. Click Generate JWT
  4. Use the token in your applications
JWT configuration

Token Structure

{
  "sub": "user@company.com",
  "workspace": "workspace-id",
  "scopes": ["read:queries", "execute:queries"],
  "exp": 1737200000
}

Connection Credentials

How Credentials Are Stored

ComponentStorage
Connection stringsAzure Key Vault
API keysEncrypted database
Service accountsManaged identity

Rotating Credentials

  1. Go to Connections
  2. Select the connection
  3. Click Update Credentials
  4. Enter new credentials
  5. Test connection
  6. Save

Credential rotation doesn't require downtime. Update, test, then save.


Best Practices

PracticeWhy
Short expiry for dev keysLimit exposure during development
Long expiry for productionAvoid service interruptions
Scope appropriatelyMinimum necessary access
Rotate regularlyLimit compromise window
Use environment variablesNever hardcode secrets

Audit Trail

Every secret operation is logged:

  • Key creation (who, when)
  • Key usage (which endpoint, when)
  • Key revocation
  • Credential updates

Access audit logs via:

  • Workspace settings → Security → Audit
  • API: GET /v1/audit/secrets

Revoking Access

Revoke an API Key

  1. Go to API → Keys
  2. Find the key
  3. Click Revoke
  4. Confirm

Revocation is immediate. Applications using that key will stop working.

Emergency Revocation


Next Steps

If you want to...Go to...
Test your APIAPIs Overview →
Manage team accessPermissions →
Understand workflowSave vs Commit →
On this page