Skip to main content
API keys authenticate the tools that talk to Switch Trust on your behalf, such as the CLI scanner, your CI/CD pipelines, and the SDK. Each key carries a role, so it can do only what that role allows. To open this page, select the Settings icon in Switch Trust, then under Admin select API keys.
Reaching this page needs the Editor role or higher. A Viewer can’t create or see API keys.

The keys list

The My keys view shows the keys you created. Use Search keys to filter it by name, and the Columns control to show or hide any of the columns below, so you only see what you need. An Admin or Org Admin also gets an All org keys view, which shows every key in the organization. With any other role, you see only your own keys, and there’s no view to switch to. Search is offered in My keys only. Each key has these columns:
  • Name is the label you gave the key when you created it.
  • Owner is the member who created it. This column appears in All org keys. It’s left out of My keys, since every key there is yours.
  • Key is a masked preview of the value. The full value is shown only once, when you create the key.
  • Role is the role the key acts with.
  • Status shows whether the key is Active, when it’s due to expire (for example, Expires today or Expires in 5 days), or Expired.
  • Created is when the key was created.
  • Expires is when the key lapses, or Never for a key with no expiration.

Create a key

1

Open the create dialog

Select Create key.
2

Name the key and set its role

Enter a Name that says where the key is used, such as “Production Scanner”. Choose the Role the key acts with, which sets what it’s allowed to do. You can scope a key to any role up to your own, and it defaults to your role.
3

Set an expiration

Choose an Expiration. You can pick a preset (1 day, 7 days, 30 days, 90 days, or 1 year) or set a custom number of days up to 365.
4

Create and copy the token

Select Create key. Switch Trust shows the full token once, with a Show or Hide control and the option to copy it.
Copy the token as soon as it’s shown. You won’t be able to see it again, and there’s no way to recover it. If you lose it, revoke the key and create a new one.
Set the token as your FLINTAI_API_KEY in the SDK, or as the secret your scanner or CI/CD integration expects. See SDK configuration for where the key goes.

Roles and key scoping

A key can act only within its role, so give each key the least access it needs. Because a key’s reach follows its owner’s role, lowering someone’s role revokes any of their keys scoped above the new one. See Roles and permissions.

Revoke a key

To turn off a key, select Revoke on its row and confirm. Revoking takes effect right away and can’t be undone, so anything still using the key stops working until you issue a new one. From the All org keys view, an Admin or Org Admin can also revoke keys other members created, not just their own.