Functions and configuration
API keys
Give servers, workers, and automation their own scoped credentials, so they can call your Project without a user password.
When to use an API key
- A backend service or worker that reads or writes Project data.
- A CI job or script that imports or exports records.
- A partner integration that needs access to a few tables only.
Never put an API key in a browser or mobile app. Anyone can read code that runs on a user's device. Those apps should sign users in instead.
Create a key
- Open your Project and select API keys.
- Select New API key and give it a clear name, such as Billing worker.
- Choose the permission: read only, or read and write.
- Under Allowed collections, pick the tables the key may use. Leave it empty to allow every table.
- Optionally set an expiry date.
- Select Create and copy the key right away. It is shown only once.
Use the key
Send the key in the X-API-Key header. The console's Copy cURL example button fills in your Project address for you.
curl "https://my-app.rustabase.net/api/v1/collections/orders/records" -H "X-API-Key: YOUR_API_KEY"import { createClient } from "rustabase";
const rb = createClient("https://my-app.rustabase.net");
const headers = { "X-API-Key": process.env.RUSTABASE_API_KEY };
const orders = await rb.from("orders").list({ sort: "-created", headers });Rotate, disable, or revoke
| Action | What happens |
|---|---|
Rotate key | Issues a new secret. The old secret stops working at once. Update your service first. |
Disable key | Stops the key working but keeps it, so you can enable it again later. |
Revoke key | Deletes the key for good. Any app using it loses access immediately. |
const rotated = await rb.admin.apiKeys.rotate("KEY_ID"); // new secret, shown onceGood practice
- Create one key per service, so you can rotate or revoke one without affecting others.
- Give each key the fewest tables and the lowest permission it needs.
- Set an expiry date for temporary access.
- Check Last used on the keys list and revoke keys nobody uses.
- Keep keys in your hosting provider's secret settings, never in a repository.
Found something wrong on this page?
Fix it yourself. The link below opens this file in GitHub's editor and forks the repository for you if you need one, and your change becomes a pull request without leaving the browser.