API keys
API keys let your backend manage TrustPort without a person signing in: creating users, assigning roles, reading the audit log and more.
Key types
| Type | Starts with | Use it for |
|---|---|---|
| Secret key | sk_live_ | Server-to-server calls to the TrustPort API. Never put it in browser or mobile code. |
| Publishable key | pk_live_ | Identifying your workspace in client-side code. It can’t call the management API. |
Create a key
- Name it after where it will live
For example “Production backend” or “Nightly user import”, so you know what breaks if you revoke it.
- Choose the type
Pick Secret key for backend use.
- Copy it now
The full key is shown once. Store it in your secret manager or environment variables. Afterwards, the dashboard only shows its prefix and when it was last used.
Use a key
Send it as a bearer token:
curl https://id.trustportidentity.com/api/v1/users \
-H "Authorization: Bearer $TRUSTPORT_API_KEY"What a secret key can do
A secret key acts as an admin of your workspace for management tasks: users, organizations, applications, roles and groups, domains, branding, email templates, webhooks, actions, Vault and the audit log.
Some things always need a real person, so keys are refused there:
- Signing in, sessions and two-factor devices
- Invitations
- Access requests and reviews
- Creating or revoking other API keys
Rotate and revoke
To rotate a key, create a new one, deploy it, then revoke the old one. Revoking takes effect straight away and can't be undone. Revoke a key immediately if it may have leaked; check the audit log for anything it did.