> ## Documentation Index
> Fetch the complete documentation index at: https://docs.frayme.io/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys

> Create the keys your systems use to submit cases, copy them once, and delete them.

export const Clip = ({id, caption}) => <Frame caption={caption}>
    <video controls muted playsInline preload="metadata" className="w-full aspect-video rounded-xl" poster={`/videos/guides/${id}.poster.png`} src={`/videos/guides/${id}.mp4`} />
  </Frame>;

export const Shot = ({id, alt, caption}) => <Frame caption={caption}>
    <img className="block dark:hidden rounded-lg" src={`/images/guides/${id}.light.png`} alt={alt} loading="lazy" decoding="async" />
    <img className="hidden dark:block rounded-lg" src={`/images/guides/${id}.dark.png`} alt={alt} loading="lazy" decoding="async" />
  </Frame>;

**Settings → API** holds the **API Keys** card. You need `apikeys:write` to create keys.

<Shot id="engineer/api-01-tab" alt="Settings API tab" caption="API keys above, webhook endpoints below." />

<Shot id="engineer/api-04-key-list" alt="API Keys card" caption="Existing keys by name and id; the value is never shown again." />

<Clip id="engineer/create-api-key" caption="Create a key, copy it once, delete it." />

## Create a key

<Steps>
  <Step title="Click Create Key">
    Give it a **Key name** that says where it is used, for example `checkout-service`.
  </Step>

  <Step title="Pick scopes">
    | Scope                                          | Allows                                                            |
    | ---------------------------------------------- | ----------------------------------------------------------------- |
    | **Create cases** (`cases:write`)               | `POST /cases`, and information requests through the API           |
    | **Read cases** (`cases:read`)                  | `GET /cases/{caseId}`, `GET /cases`                               |
    | **Deliver callbacks** (`cases:callback`)       | Post an external callback to a paused node                        |
    | **Set entity attributes** (`attributes:write`) | `POST /customer-attributes`                                       |
    | **Read tags** (`tags:read`)                    | List a case's tags                                                |
    | **Manage tags** (`tags:write`)                 | Add or remove a case's tags, restricted to the managed vocabulary |

    A request without a matching scope is rejected with 403.

    <Shot id="engineer/api-02-create-key" alt="Create API Key dialog" caption="Name and scopes." />
  </Step>

  <Step title="Copy it once">
    **API Key Created** shows the value a single time. Store it in your secret manager before clicking **Done**.

    <Shot id="engineer/api-03-key-reveal" alt="API Key Created dialog" caption="The value is shown once." />
  </Step>
</Steps>

## Use it

Send the key on every request as `X-API-Key`. See [Use the Case API](/guides/engineer/public-api).

## Delete

The bin icon asks **Delete API Key**. The key stops working immediately and every integration using it breaks.

<Shot id="engineer/api-05-delete-confirm" alt="Delete API Key dialog" caption="Deletion is immediate." />

## Not available

Keys cannot be rotated or renamed from the console. To rotate, create a new key, switch your systems, then delete the old one.
