[{"data":1,"prerenderedAt":410},["ShallowReactive",2],{"navigation_docs":3,"-guides-manage-api-keys":114,"-guides-manage-api-keys-surround":405},[4,23,85,99],{"title":5,"path":6,"stem":7,"children":8},"Getting Started","\u002Fgetting-started","1.getting-started",[9,13,18],{"title":10,"path":6,"stem":11,"icon":12},"Getting started","1.getting-started\u002Findex","i-lucide-rocket",{"title":14,"path":15,"stem":16,"icon":17},"Try the demo","\u002Fgetting-started\u002Ftry-the-demo","1.getting-started\u002F1.try-the-demo","i-lucide-monitor-play",{"title":19,"path":20,"stem":21,"icon":22},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F2.quickstart","i-lucide-play",{"title":24,"path":25,"stem":26,"children":27},"Guides","\u002Fguides","2.guides",[28,31,37,42,47,53,58,63,68,74,80],{"title":24,"path":25,"stem":29,"icon":30},"2.guides\u002Findex","i-lucide-map",{"title":32,"path":33,"stem":34,"icon":35,"group":36},"Connect a GitHub repository","\u002Fguides\u002Fconnect-a-github-repository","2.guides\u002F01.connect-a-github-repository","i-lucide-git-branch","Connect a project",{"title":38,"path":39,"stem":40,"icon":41,"group":36},"Analyze a project without GitHub","\u002Fguides\u002Fanalyze-a-project-without-github","2.guides\u002F02.analyze-a-project-without-github","i-lucide-upload",{"title":43,"path":44,"stem":45,"icon":46,"group":36},"Exclude dependency scopes","\u002Fguides\u002Fexclude-dependency-scopes","2.guides\u002F04.exclude-dependency-scopes","i-lucide-filter",{"title":48,"path":49,"stem":50,"icon":51,"group":52},"Scan from GitHub Actions","\u002Fguides\u002Fscan-from-github-actions","2.guides\u002F05.scan-from-github-actions","i-lucide-workflow","Automate",{"title":54,"path":55,"stem":56,"icon":57,"group":52},"Scan from another CI","\u002Fguides\u002Fscan-from-another-ci","2.guides\u002F06.scan-from-another-ci","i-lucide-square-terminal",{"title":59,"path":60,"stem":61,"icon":62,"group":52},"Manage API keys","\u002Fguides\u002Fmanage-api-keys","2.guides\u002F07.manage-api-keys","i-lucide-key-round",{"title":64,"path":65,"stem":66,"icon":67,"group":52},"Create many projects at once","\u002Fguides\u002Fcreate-many-projects-at-once","2.guides\u002F08.create-many-projects-at-once","i-lucide-layers",{"title":69,"path":70,"stem":71,"icon":72,"group":73},"Export reports and SBOMs","\u002Fguides\u002Fexport-reports-and-sboms","2.guides\u002F11.export-reports-and-sboms","i-lucide-download","Act on the results",{"title":75,"path":76,"stem":77,"icon":78,"group":79},"Organizations and plans","\u002Fguides\u002Forganizations-and-plans","2.guides\u002F13.organizations-and-plans","i-lucide-building-2","Organization and team",{"title":81,"path":82,"stem":83,"icon":84,"group":79},"Invite your team","\u002Fguides\u002Finvite-your-team","2.guides\u002F14.invite-your-team","i-lucide-users",{"title":86,"path":87,"stem":88,"children":89},"Core Concepts","\u002Fcore-concepts","3.core-concepts",[90,94],{"title":91,"path":87,"stem":92,"icon":93},"Core concepts","3.core-concepts\u002Findex","i-lucide-lightbulb",{"title":95,"path":96,"stem":97,"icon":98},"The health score","\u002Fcore-concepts\u002Fhealth-score","3.core-concepts\u002F1.health-score","i-lucide-gauge",{"title":100,"path":101,"stem":102,"children":103},"Reference","\u002Freference","5.reference",[104,107],{"title":100,"path":101,"stem":105,"icon":106},"5.reference\u002Findex","i-lucide-book-marked",{"title":108,"path":109,"stem":110,"children":111,"icon":113},"Supported ecosystems","\u002Freference\u002Fecosystems","5.reference\u002F1.ecosystems\u002Findex",[112],{"title":108,"path":109,"stem":110,"icon":113},"i-lucide-package",{"id":115,"title":59,"body":116,"description":398,"extension":399,"links":400,"meta":401,"navigation":402,"path":60,"seo":403,"stem":61,"__hash__":404},"docs\u002F2.guides\u002F07.manage-api-keys.md",{"type":117,"value":118,"toc":390},"minimark",[119,123,131,136,139,210,217,224,228,242,248,271,284,295,299,309,312,328,335,349,357,360,369,373],[120,121,122],"p",{},"A pipeline uses an API key to trigger a scan, push build files or create projects.\nThis page covers the two scopes, the\ncreation form, where the key belongs in your CI, and how to rotate it without\nbreaking a build.",[120,124,125,126,130],{},"You must be an ",[127,128,129],"strong",{},"owner or an admin of the organization"," to create, list or\nrevoke keys in either scope. A member cannot list them.",[132,133,135],"h2",{"id":134},"choose-the-scope","Choose the scope",[120,137,138],{},"The prefix tells the two scopes apart in a CI variable.",[140,141,142,161],"table",{},[143,144,145],"thead",{},[146,147,148,152,155,158],"tr",{},[149,150,151],"th",{},"Scope",[149,153,154],{},"Prefix",[149,156,157],{},"Reaches",[149,159,160],{},"Managed in",[162,163,164,190],"tbody",{},[146,165,166,170,176,179],{},[167,168,169],"td",{},"Project",[167,171,172],{},[173,174,175],"code",{},"dt_proj_",[167,177,178],{},"that project only",[167,180,181,182,185,186,189],{},"the project, ",[127,183,184],{},"Integrations"," tab, ",[127,187,188],{},"API Keys"," section",[146,191,192,195,200,203],{},[167,193,194],{},"Organization",[167,196,197],{},[173,198,199],{},"dt_org_",[167,201,202],{},"every project of the organization, GitHub projects and upload projects alike",[167,204,205,206,209],{},"organization settings, ",[127,207,208],{},"API keys"," tab",[120,211,212,213,216],{},"Use a project key when a repository scans itself. Use an organization key when multiple pipelines scan:\none secret in a shared variable instead of one per\nproject, and one operation to rotate instead of thirty. An organization key is\nalso the only kind that can create projects, described in\n",[214,215,64],"a",{"href":65},".",[120,218,219,220,223],{},"Using a key on a project it does not cover returns a ",[173,221,222],{},"404",", the same response as\nfor a project that does not exist. Deptools never confirms that another\norganization's project exists.",[132,225,227],{"id":226},"create-a-key","Create a key",[120,229,230,231,233,234,237,238,241],{},"Open the ",[127,232,188],{}," section for the scope you want, then click ",[127,235,236],{},"New API Key"," on a project or\n",[127,239,240],{},"New key"," on an organization.",[120,243,244,247],{},[127,245,246],{},"Name."," A label for you, up to 255 characters.\nName it after the place that will hold it.",[120,249,250,253,254,257,258,257,261,257,264,267,268,216],{},[127,251,252],{},"Expiration."," ",[173,255,256],{},"No expiration",", ",[173,259,260],{},"1 day",[173,262,263],{},"30 days",[173,265,266],{},"90 days"," or ",[173,269,270],{},"1 year",[120,272,273,276,277,279,280,283],{},[127,274,275],{},"Allow this key to create projects."," Organization keys only, and unchecked by\ndefault. Check it only if this key will provision projects through the API,\ndescribed in\n",[214,278,64],{"href":65},". That\nendpoint creates CI upload projects, and nothing else, on the ",[127,281,282],{},"Pro plan",". The\nchoice is made at creation and is never inherited: an existing scan key can\nnever gain it.",[285,286,287,290,291,294],"warning",{},[127,288,289],{},"The key is shown once, at creation."," Deptools stores a hash of it and the\nfirst characters only, ",[173,292,293],{},"dt_org_a1b2c3d4...",", which is what the list displays.\nNobody can show you the value again, support included. Copy it\nbefore you close the dialog. If you lose it, revoke it and create another.",[132,296,298],{"id":297},"revoke-and-rotate-a-key","Revoke and rotate a key",[120,300,301,304,305,308],{},[127,302,303],{},"Revoke"," removes the key immediately and permanently. There is no undo, and\nany pipeline still using it fails with a ",[173,306,307],{},"401"," on its next run. The dialog\nnames the key so you can check you are revoking the right one.",[120,310,311],{},"Rotate in this order to avoid a red build:",[313,314,315,319,322,325],"ol",{},[316,317,318],"li",{},"Create the new key, in the same scope.",[316,320,321],{},"Update the CI variable with the new value.",[316,323,324],{},"Run one pipeline and confirm the scan succeeds.",[316,326,327],{},"Revoke the old key.",[120,329,330,331,334],{},"The ",[127,332,333],{},"Last used"," column tells you whether a key is still in use before you\nrevoke it. On an organization key it tells you that someone pushed, but not which project since\nevery pipeline shares it.",[120,336,337,338,341,342,344,345,348],{},"An expiration is a rotation you schedule, not an automatic renewal. An expired\nkey is not deleted: it stays in the list marked ",[127,339,340],{},"Expired"," and answers ",[173,343,307],{},"\nwith ",[173,346,347],{},"API_KEY_EXPIRED",". Starting fourteen days before the date, the list shows\nthe days remaining in amber, which is your window to run the four steps above.",[350,351],"u-color-mode-image",{"alt":352,"className":353,"dark":355,"light":356},"Organization API keys list, with a key that can create projects, a key expiring soon and an expired key",[354],"wide-capture","\u002Fimages\u002Fdocs\u002Fguides\u002Fmanage-api-keys-1-keys-list-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Fmanage-api-keys-1-keys-list-light.webp",[120,358,359],{},"Two lifecycle rules are worth knowing before you plan a rotation:",[361,362,363,366],"ul",{},[316,364,365],{},"Deleting a project deletes the keys bound to it. Organization keys are\nunaffected and keep working on the remaining projects.",[316,367,368],{},"A key outlives the person who created it. A departure never breaks a pipeline.",[132,370,372],{"id":371},"next-steps","Next steps",[361,374,375,380,385],{},[316,376,377,379],{},[214,378,48],{"href":49}," to use the key in\na workflow.",[316,381,382,384],{},[214,383,54],{"href":55}," for GitLab, Jenkins and\nthe rest.",[316,386,387,389],{},[214,388,64],{"href":65}," to use a\nkey that has the create permission.",{"title":391,"searchDepth":392,"depth":392,"links":393},"",2,[394,395,396,397],{"id":134,"depth":392,"text":135},{"id":226,"depth":392,"text":227},{"id":297,"depth":392,"text":298},{"id":371,"depth":392,"text":372},"Create, store and revoke the project and organization keys used by your pipelines.","md",null,{},{"icon":62,"group":52},{"title":59,"description":398},"OFMNwrRPm9jRL9gNRf8miv0Zbaj38r1n9BpYuvJHTro",[406,408],{"title":54,"path":55,"stem":56,"description":407,"icon":57,"group":52,"children":-1},"Trigger and poll a scan with curl from GitLab CI, Jenkins or any other pipeline.",{"title":64,"path":65,"stem":66,"description":409,"icon":67,"group":52,"children":-1},"Provision a whole portfolio of CI upload projects in one API request, and get back the name to UUID mapping your pipelines need.",1787263157379]