API keys and rotation
Divyam API keys authenticate application requests. Manage them from API Keys after signing into the console.
Create a key
- Select API Keys in the left navigation.
- Select Create API key.
- Enter a recognizable Key name, such as
customer-app-test. - Select Create key.
- Select Copy key and store the complete credential in your application’s secret settings.
- Check I understand this key will not be shown again, then select Done.
Active key names must be unique. Names can contain up to 100 characters. The complete key appears once. The inventory’s display hint cannot replace it. If you lose the secret, create a replacement and revoke the lost key.
Keep keys in trusted application settings, backend environment variables, or your existing secret manager. Do not commit them or include them in browser JavaScript.
Find or rename a key
The inventory lists active keys with their names, display hints, creation dates, and last-used dates. Use Search by name or Sort by to find one.
Select Rename, change the name, then select Save name. Renaming changes the label. The application’s credential stays the same.
Set DIVYAM_API_KEY in a terminal
The integration guides read the key from DIVYAM_API_KEY.
In Bash, run these commands, paste your key at the prompt, and press Enter:
read -rsp 'Divyam API key: ' DIVYAM_API_KEY
printf '\n'
export DIVYAM_API_KEY
read sets the variable without displaying your input. export passes it to applications started from that terminal.
A new terminal needs the variable set again.
For a deployed application, use its normal secret configuration instead.
Rotation
Rotate a key by moving every application using it to a replacement before revoking it. First identify those applications and check that your account can create another active key.
- Create a replacement with a distinct name, such as
customer-app-test-next. - Store the new secret securely.
- Update each application’s connection or secret configuration.
- Restart or reload the application if its configuration requires that.
- Send a new request from the application and verify the expected answer.
- Find that request in Logs using its time and requested model.
- Confirm every application using the old key has moved to the replacement.
- In API Keys, select the checkbox beside the old key only.
- Select Revoke selected and review the number of selected keys.
- Check the permanent-action acknowledgement, then select Revoke 1 key for a single-key rotation.
- Verify the replacement application still succeeds after revocation.
Revocation cannot be undone. New requests using a revoked key receive HTTP 401. Do not use Revoke all for routine rotation.
Key limits
Your account’s plan limits the number of active keys. If creation reaches that limit, the error explains the allowance.
Revoke an unused key to free a slot, after confirming no application needs it. If all keys are in use, ask your Divyam administrator about capacity before starting rotation. Revoking a working key first interrupts applications using it until a replacement is deployed.
Revoke an unused or exposed key
- Identify the key by name and display hint.
- Select its checkbox, then select Revoke selected.
- Review the selected count and acknowledge the permanent action.
- Confirm revocation. Update any application that still needs access with a replacement key.
For an exposed key, revoke the affected credential promptly. If you cannot identify it, Revoke all stops every active key on the account. Applications using those keys will fail until you deploy replacements.
If bulk revocation reports partial failure, select the remaining keys and retry. Use Troubleshooting for authentication failures.