API Keys
Create, scope, store, and rotate Syper API keys.
DraftDescribes the intended design. Not yet available — names, fields and behaviour may change.
API keys identify your application to Syper. Each key belongs to one environment and carries a set of permissions.
Handling keys
- Store secret keys in a secrets manager or environment variables — never in source control.
- Use a separate key per service or device fleet so you can revoke one without affecting others.
- Grant each key the narrowest permissions that work.
- Rotate keys on a schedule and immediately if one may have leaked.
Rotation
Rotation is designed to be zero-downtime: create a new key, deploy it, confirm traffic has moved in Logs, then revoke the old key.
Managing keys
Keys will be managed from the Developer Dashboard and the CLI.
Last updated on