API keys and security
API keys and security
Section titled “API keys and security”REST calls authenticate with the X-API-Key header.
Use the Admin key only for administration. Create role-specific keys for integrations where possible.
Keep secrets out of diagnostics
Section titled “Keep secrets out of diagnostics”Never include these values in screenshots, tickets or logs:
- Admin or integration API keys;
- Automation Hub licence keys;
- database connection strings;
- TLS private keys;
- customer data.
The local Console shows status and key metadata without rendering stored raw keys.
Admin key rejected after upgrade
Section titled “Admin key rejected after upgrade”Open the local Console first:
http://127.0.0.1:8844/console
Check the Hub version, licence state and MCP key status before replacing configuration. Existing paid upgrades should preserve the established service/config identity.