TrustPortDocs

Key types

TypeStarts withUse it for
Secret keysk_live_Server-to-server calls to the TrustPort API. Never put it in browser or mobile code.
Publishable keypk_live_Identifying your workspace in client-side code. It can’t call the management API.

Create a key

In the dashboardAPI Keys›Generate API key
  1. Name it after where it will live

    For example “Production backend” or “Nightly user import”, so you know what breaks if you revoke it.

  2. Choose the type

    Pick Secret key for backend use.

  3. Copy it now

    The full key is shown once. Store it in your secret manager or environment variables. Afterwards, the dashboard only shows its prefix and when it was last used.

Use a key

Send it as a bearer token:

List users
curl https://id.trustportidentity.com/api/v1/users \
  -H "Authorization: Bearer $TRUSTPORT_API_KEY"

What a secret key can do

A secret key acts as an admin of your workspace for management tasks: users, organizations, applications, roles and groups, domains, branding, email templates, webhooks, actions, Vault and the audit log.

Some things always need a real person, so keys are refused there:

  • Signing in, sessions and two-factor devices
  • Invitations
  • Access requests and reviews
  • Creating or revoking other API keys

Rotate and revoke

To rotate a key, create a new one, deploy it, then revoke the old one. Revoking takes effect straight away and can't be undone. Revoke a key immediately if it may have leaked; check the audit log for anything it did.

Treat secret keys like admin passwords. Keep one key per service so a leak is easy to contain.
© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.