Skip to content

API keys and security

REST calls authenticate with the X-API-Key header.

Use the Admin key only for administration. Create role-specific keys for integrations where possible.

Never include these values in screenshots, tickets or logs:

  • Admin or integration API keys;
  • Automation Hub licence keys;
  • database connection strings;
  • TLS private keys;
  • customer data.

The local Console shows status and key metadata without rendering stored raw keys.

Open the local Console first:

http://127.0.0.1:8844/console

Check the Hub version, licence state and MCP key status before replacing configuration. Existing paid upgrades should preserve the established service/config identity.