Create a Scoped API Key for an App, a Script or a Contractor

Data Security

A scoped API key does one job, on the indexes you choose, for as long as you decide. Give one to every app, script and contractor instead of your master key.

01 · Create it

Open Account › API Keys

Click + Create a scoped key.

Name the key

After its job, so you still know it in six months: Search key for the mobile app, CI ingest for staging.

Tick only what it needs

Under What may this key do?, tick the endpoints. The filter and select all help.

Pick the indexes

Under Which indexes may it touch?: All of my indexes, some of them, or a name pattern. * stands for any characters and ? for one, so sandbox_* covers every index whose name starts with sandbox_.

Set an expiry date, if it is temporary

Optional. After that date the key stops working.

Create the key and copy it

Treat it like a password. If it leaks, regenerate just that key.

02 · Use it

Exactly like the master key: send it as api_key, with the email of the account that created it.

curl "https://api.opensolr.com/solr_manager/api/embed_and_search?email=OWNER_EMAIL&api_key=YOUR_SCOPED_KEY&core_name=your_index&q=hello"

A call outside the key's scope answers 403: ERROR_SCOPED_KEY_ENDPOINT_NOT_ALLOWED for an endpoint you did not tick, ERROR_SCOPED_KEY_CORE_NOT_ALLOWED for an index it may not touch.

03 · Manage it

Each key in Your scoped keys has Edit, Revoke (and Enable again), Regenerate and Delete, and shows when it was last used. More: API authentication and keys and Master API key vs scoped API keys.