ProdgatorDocs
Administration

API keys

Create, scope, use and revoke organization API keys for the Prodgator v1 REST API.

API keys let scripts, dashboards and CI jobs call the Public REST API (v1) without a user session. A key belongs to the organization, not to the person who created it.

Availability

API keys need a plan with API access:

PlanActive keys
Free, TeamNone
Business10
Enterprise50

Only admins can see and manage keys. Admin Console > API keys does not appear on Free or Team; upgrade to Business to see it.

Create a key

  1. Open Admin Console > API keys.
  2. Click Create key.
  3. Enter a Name (1 to 64 characters), for example "CI pipeline dashboard".
  4. Pick at least one scope.
  5. Pick when it Expires: 30 days, 90 days (the default), 1 year or no expiry.
  6. Click Create key and copy the key.

The full key is shown once. Store it in a secret manager; it cannot be recovered. If you lose it, revoke it and create a new one.

Scopes

Give a key only the scopes it needs.

ScopeLabel in ProdgatorAllows
Read pipelinesList and read pipeline runs
Read deploymentsList and read deployments
Read security alertsList and read security alerts
Read complianceList compliance results
Approve deploymentsApprove or reject deployments waiting on Prodgator's protection rule
Upload security reportsUpload SARIF, CycloneDX and SPDX reports
Send Claude Code telemetryPost Claude Code OpenTelemetry logs

A key with must have no other scope. Make one such key for each source. See Claude Code telemetry.

Scopes are fixed when the key is created. To change them, create a new key.

A key with must always give a reason of 10 to 500 characters, and cannot answer GitHub required-reviewer gates, which need a person's own GitHub account.

Key format

Keys start with in production and in development. A key only works in the environment that issued it.

Using a key

Send the key as a bearer token:

curl -s \
  -H "Authorization: Bearer $PRODGATOR_API_KEY" \
  "https://api.prodgator.io/v1/runs?status=failure&limit=25"

Requests are rate limited. Retry responses with backoff.

Revoke a key

In Admin Console > API keys, click revoke on the key's row and confirm with Revoke key. Requests using it start failing within about a minute. Revoking cannot be undone.

Expired keys still count toward your plan's key limit until you revoke them. The page shows how many of your allowed keys are in use.

On this page