A scoped API key does one job, on the indexes you choose, for as long as you decide. Give one to every app, script and contractor instead of your master key.
01 · Create it
Open Account › API Keys
Click + Create a scoped key.
Name the key
After its job, so you still know it in six months: Search key for the mobile app, CI ingest for staging.
Tick only what it needs
Under What may this key do?, tick the endpoints. The filter and select all help.
Pick the indexes
Under Which indexes may it touch?: All of my indexes, some of them, or a name pattern. * stands for any characters and ? for one, so sandbox_* covers every index whose name starts with sandbox_.
Set an expiry date, if it is temporary
Optional. After that date the key stops working.
Create the key and copy it
Treat it like a password. If it leaks, regenerate just that key.
02 · Use it
Exactly like the master key: send it as api_key, with the email of the account that created it.
curl "https://api.opensolr.com/solr_manager/api/embed_and_search?email=OWNER_EMAIL&api_key=YOUR_SCOPED_KEY&core_name=your_index&q=hello"
A call outside the key's scope answers 403: ERROR_SCOPED_KEY_ENDPOINT_NOT_ALLOWED for an endpoint you did not tick, ERROR_SCOPED_KEY_CORE_NOT_ALLOWED for an index it may not touch.
03 · Manage it
Each key in Your scoped keys has Edit, Revoke (and Enable again), Regenerate and Delete, and shows when it was last used. More: API authentication and keys and Master API key vs scoped API keys.