Developer Access and API Keys
The Developer hub is where you issue an API key, point webhooks at your own systems and watch how much of the API you are using. This guide explains what each part does and what the API can reach.
What the Developer Hub Is For
The Developer hub gives you programmatic access to your own account. It is a second way into data you can already see on screen, meant for a spreadsheet, a personal dashboard or a script that reconciles holdings against another source. It is not a way to reach anyone else’s data.
- Settings: the default tab, holding your usage figures, your API keys and your webhook endpoints
- API Docs: the reference for every endpoint, rendered inside the page rather than kept on a separate site, so it always matches the version you are calling
Landing straight on the reference
Adding ?tab=docs to the Developer address opens the API Docs tab directly. Switching tabs updates the address as you go, so a browser back button returns you to the tab you came from and a link you save reopens where you left it.
Issuing and Using a Key
A key is created from the API Keys section and is sent as a bearer token on each request. The Quick start block on the hub shows the shape of a first call: a request for your current holdings, with the key placeholder for you to replace.
- Treat a key as a password: anyone holding it can read what your account can read, so keep it out of shared documents and out of anything published
- How many you can hold depends on your plan: the hub shows your own allowance rather than a fixed number, so the figure on screen is the one that applies to you
- Rotate rather than share: issue a separate key per tool, so retiring one integration does not break the others
Managing a key after it is issued
Each key in the API Keys section has Edit and Rotate actions alongside Revoke. Edit changes the key’s name, the scopes it carries (only the scopes your plan allows are offered) and its expiry date, which you can extend or clear. A change of scopes takes effect on the key’s very next request.
- Last used: each key shows when it was last used and from which address, so a key nobody uses, or one used from an address you do not recognise, stands out
- Expiring soon: a key nearing its expiry date is marked in the hub and we email you ahead of time, so an integration does not stop without warning
- Revoked keys: Show revoked keys lists every key you have revoked, with its name, prefix, when it was created, last used and revoked
Rotating a key during a credential incident
If a key may have been exposed, replace its secret straight away. Rotating keeps the same key, with its name, scopes and usage history, and issues a new secret. The old secret stops working on the next request, so the integration using it will fail until it has the new one.
- 1. Rotate or create: choose Rotate on the key and confirm. If you would rather switch over without any interruption, create a second key with the same scopes instead, if your plan’s key allowance has room
- 2. Copy the new secret: it is shown once only. Store it in the same secure place as the one it replaces
- 3. Deploy: update the integration or tool to send the new secret
- 4. Verify: make one request with the new secret and check the key’s Last used time updates in the hub
- 5. Revoke: if you created a second key, revoke the old one. It then appears under Show revoked keys for your records
Webhooks and Usage
Webhook endpoints
A webhook endpoint is an address of yours that we call when something changes, so your own system does not have to poll for it. Webhooks sit behind their own entitlement, separate from the API itself: when your plan does not include them the section is still shown, greyed out, so you can see what is on the other side of an upgrade rather than guessing.
Usage figures
The usage panel reports what your keys have actually called. It is worth a look before you build anything that runs on a schedule, so that a loop firing more often than you intended shows up as a number rather than as a surprise.
Who Can Use the API
API access is a paid-plan feature. If your plan does not include it the hub replaces the settings with an upgrade panel that names the plan you need and lists what it unlocks, so the answer comes from your account rather than from a table in an article that could fall out of date.
The panel loads a moment after the page, because the entitlement is read from your subscription rather than assumed. A brief placeholder in that gap is expected, not a failure.
The Hub in a Professional View
Switching to a professional or organisation view changes what the Developer hub offers, because the professional API surface is not available yet. Rather than show consumer controls that would act on the wrong account, the hub shows a short note inviting you to get in touch about early access.
Older addresses still work
If you saved the Developer page or the API reference under an earlier portfolio address, those links still resolve. The hub now lives under your account, and the old addresses lead to the same place.
Can’t find what you’re looking for?
Our support team is here to help. Contact us and we’ll get back to you as soon as possible.
Contact Support
