API keys
Create, scope, use and revoke organization API keys for the Prodgator v1 REST API.
API keys let scripts, dashboards and CI jobs call the Public REST API (v1) without a user session. A key belongs to the organization, not to the person who created it.
Availability
API keys need a plan with API access:
| Plan | Active keys |
|---|---|
| Free, Team | None |
| Business | 10 |
| Enterprise | 50 |
Only admins can see and manage keys. Admin Console > API keys does not appear on Free or Team; upgrade to Business to see it.
Create a key
- Open Admin Console > API keys.
- Click Create key.
- Enter a Name (1 to 64 characters), for example "CI pipeline dashboard".
- Pick at least one scope.
- Pick when it Expires: 30 days, 90 days (the default), 1 year or no expiry.
- Click Create key and copy the key.
The full key is shown once. Store it in a secret manager; it cannot be recovered. If you lose it, revoke it and create a new one.
Scopes
Give a key only the scopes it needs.
| Scope | Label in Prodgator | Allows |
|---|---|---|
| Read pipelines | List and read pipeline runs | |
| Read deployments | List and read deployments | |
| Read security alerts | List and read security alerts | |
| Read compliance | List compliance results | |
| Approve deployments | Approve or reject deployments waiting on Prodgator's protection rule | |
| Upload security reports | Upload SARIF, CycloneDX and SPDX reports | |
| Send Claude Code telemetry | Post Claude Code OpenTelemetry logs |
A key with must have no other scope. Make one such key for each source. See Claude Code telemetry.
Scopes are fixed when the key is created. To change them, create a new key.
A key with must always give a reason of 10 to 500 characters, and cannot answer GitHub required-reviewer gates, which need a person's own GitHub account.
Key format
Keys start with in production and in development. A key only works in the environment that issued it.
Using a key
Send the key as a bearer token:
curl -s \
-H "Authorization: Bearer $PRODGATOR_API_KEY" \
"https://api.prodgator.io/v1/runs?status=failure&limit=25"Requests are rate limited. Retry responses with backoff.
Revoke a key
In Admin Console > API keys, click revoke on the key's row and confirm with Revoke key. Requests using it start failing within about a minute. Revoking cannot be undone.
Expired keys still count toward your plan's key limit until you revoke them. The page shows how many of your allowed keys are in use.