Restrict what an API key can do
Give each integration read or write access to only the resources it uses.
A restricted key can only do what you allow, resource by resource. Give each integration only what it uses, so a leaked key can do as little as possible.
Set its access
Choose Restricted when you create a key, or Edit access on an existing one, then set None, Read or Write for each of:
- Payments
- Links
- Customers
- Wallet
- Webhooks
- Events (read only)
- Checkout settings
Reading needs Read, and anything that creates or changes needs Write.
An example
A store that creates payments and fulfills orders on webhooks needs Write on Payments and nothing else. A reporting tool needs Read on Payments and Customers.
Was this article helpful?