{"id":9668,"date":"2026-03-20T15:26:53","date_gmt":"2026-03-20T15:26:53","guid":{"rendered":"https:\/\/www.process.st\/help\/?post_type=ht_kb&#038;p=9668"},"modified":"2026-03-20T16:12:04","modified_gmt":"2026-03-20T16:12:04","slug":"restricted-api-keys","status":"publish","type":"ht_kb","link":"https:\/\/www.process.st\/help\/docs\/restricted-api-keys\/","title":{"rendered":"Restricted API keys"},"content":{"rendered":"<p>Restricted API keys let you scope an API key user&#8217;s access to specific resources \u2014 workflows, pages, forms, files, or data sets. Instead of giving an API key full admin access, you can limit it to exactly what it needs.<\/p>\n<blockquote><p><strong>Availability:<\/strong> Restricted API keys are available on Enterprise plans.<\/p><\/blockquote>\n<h2>How restricted API keys work<\/h2>\n<p>Every API key has an associated API key user in your organization. By default, that user is created as an Admin. With restricted API keys, you can change the user&#8217;s role and grant access to only the specific resources it needs.<\/p>\n<p>API key users have a few important properties:<\/p>\n<ul>\n<li>They&#8217;re never added to the <strong>All Organization<\/strong> group.<\/li>\n<li>They only see resources you explicitly share with them.<\/li>\n<li>Their role and permissions can be updated at any time.<\/li>\n<\/ul>\n<h2>Manage API key user access<\/h2>\n<p>To view and manage your API key users, go to <strong>Users &amp; Guests<\/strong> \u2192 <strong>API Key Users<\/strong>.<\/p>\n<p>From there you can:<\/p>\n<ul>\n<li>See all API key users in your organization<\/li>\n<li>Change a API key user&#8217;s role<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-9673\" src=\"https:\/\/www.process.st\/help\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-20-at-5.02.46-PM-1024x776.png\" alt=\"\" width=\"1024\" height=\"776\" srcset=\"https:\/\/www.process.st\/help\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-20-at-5.02.46-PM-1024x776.png 1024w, https:\/\/www.process.st\/help\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-20-at-5.02.46-PM-300x227.png 300w, https:\/\/www.process.st\/help\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-20-at-5.02.46-PM-768x582.png 768w, https:\/\/www.process.st\/help\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-20-at-5.02.46-PM-1536x1164.png 1536w, https:\/\/www.process.st\/help\/wp-content\/uploads\/2026\/03\/Screenshot-2026-03-20-at-5.02.46-PM-2048x1553.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<h2>Create a restricted API key<\/h2>\n<ol>\n<li>Go to <b>Integrations<\/b>.<\/li>\n<li>Click <strong>+ New API Key<\/strong>.<\/li>\n<li>Give the key a name.<\/li>\n<li>Go to <strong>Users &amp; Guests\u00a0<\/strong>and filter by\u00a0<strong>API Key Users<\/strong>.<\/li>\n<li>Set the user&#8217;s role. Choose Builder role for the most flexibility.<\/li>\n<li>Go to the specific workflows, pages, forms, files, or data sets and assign the appropriate permissions to the API key user with the key name you created.<\/li>\n<\/ol>\n<h2>Frequently asked questions<\/h2>\n<h3>Can I update an existing API key&#8217;s permissions?<\/h3>\n<p>Yes. Go to <strong>Users &amp; Guests<\/strong> \u2192 <strong>API Key Users<\/strong>, find the key, and edit its role, then go to each workflow, form, file, etc and assign the API key user to it. Changes take effect immediately.<\/p>\n<h3>What happens if I give an API key Admin access?<\/h3>\n<p>It behaves the same as a full admin API key. No resources are restricted unless you explicitly limit them.<\/p>\n<h3>Are API key users counted toward my seat limit?<\/h3>\n<p>API key users are separate from your regular user seats. Check your plan details for specifics.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Restricted API keys let you scope an API key user&#8217;s access to specific resources \u2014 workflows, pages, forms, files, or data sets. Instead of giving an API key full admin access, you can limit it to exactly what it needs. Availability: Restricted API keys are available on Enterprise plans. How restricted API keys work Every [&hellip;]<\/p>\n","protected":false},"author":2,"template":"","meta":{"_acf_changed":false,"available_plan":"Enterprise","available_product":"Integrations","footnotes":""},"ht_kb_category":[194],"ht_kb_tag":[],"class_list":["post-9668","ht_kb","type-ht_kb","status-publish","hentry","ht_kb_category-integrations"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/9668","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb"}],"about":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/users\/2"}],"version-history":[{"count":6,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/9668\/revisions"}],"predecessor-version":[{"id":9675,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/9668\/revisions\/9675"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/media?parent=9668"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb_category?post=9668"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb_tag?post=9668"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}