Scoped API Keys: Restrict Keys per Endpoint and Index, Stop Sharing Your Master Key
Scoped API keys — stop sharing your master key. You can now create additional API keys from Account › API Keys, each restricted to exactly the endpoints you tick and, optionally, to a chosen subset of your indexes. Give a developer search-only access to one index, give your CI pipeline Data Ingestion rights and nothing else, or hand a contractor a key that expires on a date you choose. Keys can be revoked or regenerated instantly, and your master key — which is root-level and doubles as the initial index password — never has to leave your hands. Details in the Security & Trust Center.