logoPofano

API Tokens & Keys

Managing your API tokens and keys.

Overview#

API tokens (also called API keys) are the credentials used to authenticate your requests to the Pofano API. Each token is linked to your account and can be individually managed.

What Are API Tokens?#

An API token is a unique string that identifies you as a user and authorizes your API requests. When you include a valid token in your request, Pofano:

  • Authenticates your identity.
  • Tracks your usage for billing.
  • Enforces quotas and rate limits.
  • Routes requests based on your access permissions.

Creating Tokens#

  1. Go to the API Keys section in the console.
  2. Click Create Key.
  3. Give your key a descriptive name (e.g., "Production App", "Testing").
  4. Optionally set a quota limit to cap spending on this key.
  5. Optionally set an expiration date for temporary access.
  6. Click Create and copy the key immediately.

Important: Store keys securely. The current dashboard allows authorized users to load and copy the full key again later, so dashboard access should be protected just as carefully as the key itself.

Setting Quotas and Expiration#

  • Quota limit: The maximum amount of quota this key can consume. Once reached, requests with this key will return 403 Forbidden.
  • Expiration: The key will automatically become invalid after the set date.

Token Groups#

You can organize tokens into groups for easier management. Groups can share quota limits and access configurations.

Monitoring Usage#

From the console, you can view usage statistics per token:

  • Total requests made.
  • Quota consumed.
  • Token usage over time.
  • Current status (active, expired, revoked).

Best Practices#

  • Create separate keys for different applications.
  • Set conservative quota limits on new keys.
  • Rotate keys periodically.
  • Revoke keys immediately if compromised.

On this page