# API Keys

Source: https://docs.sliplane.io/teams/api-keys

Learn how to create and manage API keys for the Sliplane API.

API keys allow you to programmatically manage your Sliplane resources through the [Sliplane API](https://ctrl.sliplane.io/#description/introduction).

## Creating an API Key

To create an API key, navigate to the [API tab](https://sliplane.io/app/team/api) in your team settings.

If your team doesn't have API access yet, request it there before creating a key.

> **warn**
>
> API keys are shown only once when created. Make sure to copy and store them securely.

## Permissions

When you create a key, give each area **None**, **Read**, or **Write**. Write includes read. The **All** row at the top sets every area at once. The areas are:

| Area                 | Covers                                                                |
| -------------------- | --------------------------------------------------------------------- |
| Projects             | Creating, renaming, and deleting projects                             |
| Services             | Services, deploys, env variables, volumes, domains, logs, and metrics |
| Servers              | Servers, rescaling, disks, and server volumes                         |
| Postgres             | Managed Postgres databases, restores, and insights                    |
| Buckets              | Object storage buckets, CORS rules, and bucket keys                   |
| SSH keys             | Team SSH keys                                                         |
| Registry credentials | Private container registry credentials                                |
| OAuth clients        | OAuth clients of the team                                             |

A CI pipeline that only deploys, for example, needs nothing more than **Write** on Services.

### Secrets

The **Secrets** row is either **None** or **Read**. With **None**, a key still sees which environment variables exist, but the values come back empty. The same goes for database passwords and connection strings. Rotating Postgres credentials needs Secrets on **Read**, because the response contains the new password.

Env variables you marked as secret are never returned by the API, whatever the key's permissions.

Keys created before custom permissions existed keep their old access, secrets included.

## Managing API Keys

You can rename, change the permissions of, and delete your existing keys from the [API tab](https://sliplane.io/app/team/api). Permission changes apply to the very next request. If you suspect a key has been compromised, delete it immediately and create a new one.
