---
title: "API keys"
description: "API keys authenticate approved machine-to-machine integrations. The first-party Configure Embed public deployment does not use an organization API key in the browser; it exchang…"
url: "https://sotaagents.ai/manual/admin-console/api-keys"
generated_by: "sotaagents-ldp"
docs_index: "https://sotaagents.ai/manual/llms.txt"
locale: "en"
---

# API keys

API keys authenticate approved machine-to-machine integrations. The first-party _Configure Embed_ public deployment does not use an organization API key in the browser; it exchanges its publish/embed identity for a constrained guest session. If you only use chat or the built-in public widget, do not create a key for that purpose.

1. #### Open API Keys

   Go to _Console → Your org → API Keys_ in the left sidebar.

![The API Keys screen listing keys with their public key, scope, status, last use and creation date](/manual/assets/product/console-api-keys-20260813.webp)
_Each key shows its scope and whether it has ever been used._

2. #### Create a key

   Click _Create API Key_ (top-right). A dialog opens — enter an optional **Name** (e.g. "Production environment") to identify it later, then click _Create_.

![The Create API Key dialog with a name entered](/manual/assets/product/console-api-key-dialog-20260813.webp)
_The name is only a label for you; it does not affect what the key can do._

3. #### Save the key and secret immediately

   The "API Key created" screen is shown **only once**. It displays both the **API Key** (format: `sota_ek_…`) and the **API Secret**. Copy both now and store them securely — they cannot be retrieved after you close this screen.

![The dialog shown once after creation, with the API key, the masked secret, and a warning that the secret will not be shown again](/manual/assets/product/console-api-key-created-20260813.webp)
_The secret is shown once. Copy it before closing this dialog._

4. #### Confirm and close

   After saving, click _I have saved the Secret_ to close the dialog.

5. #### Use the key in approved API calls

   Use the key only with the machine API and scopes documented for your integration. Its main use is signing the ticket handshake that puts SotaAgents inside your own systems — see [Embedding SotaAgents in your own systems](/manual/enterprise-integration/embedding-in-your-systems). For a public guest widget, use _Workspace → Configure Embed_ instead.

6. #### Disable a key

   To stop using a key without deleting it, click the _Actions_ button on the key's row and choose _Disable_. Confirm in the dialog. The key stops working immediately and remains visible in the list in a disabled state.

> [!WARNING]
> Keep keys secret
>
> Never commit API keys to source control or share them in chat. Treat them like passwords. If a key is exposed, disable it immediately and create a new one.
