Skip to main content

Allowing Users to Create API Keys

The site-wide Allow Users To Create API Keys setting controls whether users can create credentials for their own integrations. This lets Site Administrators keep control of integration credentials while users continue working in the Files.com apps. User keys remain subject to the associated user's permissions and the key's access scope.

By default, only Site Administrators can create these integration keys. Enabling the setting lets other users create their own.

When the setting is disabled, users who are not Site Administrators cannot create API keys for their own integrations. Site Administrators can create or remove API keys for individual users.

The setting governs creation only. Disabling it does not revoke existing keys or prevent users from listing, managing, or deleting keys they are otherwise authorized to manage, including keys created for them by an administrator. The user's account-management permissions still apply.

Whether the setting is enabled or disabled, users who are not Site Administrators cannot view or manage API keys for other users.

To end an integration's existing access, revoke its key or apply the appropriate account control. API Keys explains how the creation policy differs from key scope, expiration, and revocation.

The Desktop App and Mobile App automatically receive dedicated API keys when users sign in. These keys serve as long-lived session tokens, keeping the apps connected between uses so users do not have to repeat the sign-in process each time they return to their files. Issuing these tokens is part of app sign-in and cannot be disabled with Allow Users To Create API Keys. Users do not need permission to create integration keys to sign in to either app.

The site's separate Desktop App Session Lifetime and Mobile App Session Lifetime settings control how long each app's session tokens remain valid. This separates how often app users must sign in again from whether they can create credentials for integrations.

App session keys appear in the user's API key list returned by GET /user/api_keys, but they are not shown in the web interface's API key list. Their presence in an API response does not mean that the user has been allowed to create integration keys.