Create and revoke API keys

Updated July 21, 2026

Issue workspace keys to call the Venue API from your own code. Revoke them when you no longer need them.

What it’s for

API keys let workspace admins authenticate to the Venue API with a Bearer token (`vk_live_…`). A key carries the same access as a workspace admin, so treat it like a password: create it when you need an integration, copy the secret once, and revoke it as soon as it is unused.

Endpoints, Try-it, and code samples live in the in-app API documentation (`/docs`).

  1. Open Settings → API keys. Only workspace admins can manage keys.

  2. The list shows each key’s name, prefix (`vk_live_…`), dates, and status. Filter Active / All to hide or show revoked and expired keys.

    Switch to All to see revoked or expired keys alongside active ones.
  3. Click “Create key”, give it a name (e.g. “Production integration”), pick an expiration (30 days, 90 days, 1 year, or never), then confirm.

  4. Copy the secret immediately. It is shown only once. Tick “I’ve saved this key somewhere safe” before closing. You can open “Try in API docs” to paste it into the docs Try-it panel (it stays in this browser only).

  5. To stop a key, click “Revoke” on its row and confirm. Any integration using that key stops working right away. This can’t be undone.

Good to know

  • Never commit API keys to source control or share them in chat or tickets.
  • Expired keys stop working automatically; revoked keys stay in the All filter for audit.
  • Non-admins see the tab but cannot create or revoke keys. Ask a workspace admin.

Related articles

Still need help?

Ask AI for a docs-grounded answer, or talk to our team.

Was this article helpful?