# Creating and managing API keys

- URL: https://www.usewisecost.com/help/api/creating-and-managing-api-keys
- Audience: Admins
- Last updated: 2026-09-19
- Part of the WiseCost Help Center: https://www.usewisecost.com/help

> Create a WiseCost API key in Company Setup → API keys with a name, scopes and optional expiration. The secret is shown once; revoking works instantly.

To create a WiseCost API key, go to **Company Setup → API keys**, click **Create API key**, give it a name, choose its scopes and, if you want, an expiration. The secret is shown only once, when the key is created, so copy it then. You can revoke a key from the same table at any time, and it stops working immediately.

**Who can do this:** Administrators only.

## Create a key

1. Go to **Company Setup → API keys**. You can also get there from **Company Setup → Company settings → General**, under **Security**, with **Manage API keys**.
2. Click **Create API key**.
3. Enter a name that identifies the integration, for example "Data warehouse sync".
4. Choose the scopes the integration needs:
   - `time_activities:read`
   - `catalog:read`
   - `labor_distribution:read`
5. Optional: set an expiration date.
6. Create the key and **copy the secret now**. After you close the dialog only its prefix is visible, and the secret cannot be shown again.

[Screenshot: API keys page with the Create API key button]

[Screenshot: Create API key dialog with name, scopes and optional expiration]

## Use the key

Send it in the `Authorization` header of every request, as `Authorization: Bearer` followed by your key. The endpoints and parameters are in the reference.

[Open the API reference](https://app.usewisecost.com/api/docs)

## Revoke a key

1. Go to **Company Setup → API keys**.
2. Revoke the key from its row in the table.

It stops working at that moment. A key is never deleted: it stays in the list as revoked, and both creating and revoking are recorded in the [Audit Trail](https://www.usewisecost.com/help/reports-and-audit-trail/audit-trail).

## Good practices

- One key per integration, so you can revoke one without breaking the others.
- The minimum scopes each integration needs.
- Revoke any key that is no longer used.
- Store the secret in a secrets manager, never in code or in a shared document.

## Common questions

### I lost the secret of my API key. Can I see it again?

No. It is shown once. Revoke that key and create a new one.

### Can a team member create API keys?

No. Only admins can create and revoke them.

### What happens to an integration when I revoke its key?

Its requests are rejected from that moment on.
