Settings & integrations
Create and manage an organization API key
Create a scoped Secorvia API key under a service identity, store its one-time secret, and rotate it without losing attribution.
Reviewed
Before you start
You need permission to manage API keys in the intended organization and a secure place to store the issued key.
Create a named integration key
Open API Keys → New API key. Give each integration its own Name, such as CI pipeline, so it can be revoked independently.
Choose the service identity
Select an existing service identity or create a New identity. Finding changes and comments made by the key are attributed to this identity. Reusing the identity for a replacement key preserves attribution during rotation.
Grant only the required scopes
Choose Scopes for the integration’s actual task. Read and write scopes do not imply one another. The current form includes findings, inventory, cloud accounts, scans, vulnerabilities, compliance, and security graph scopes. Scans write requires an Idempotency-Key on each request.
Set expiry and save the one-time key
Set Expires if needed, create the key, and copy it to a secret manager or an environment variable. Confirm that you have copied it before closing. The key cannot be shown again and must not go into a browser bundle, URL, or source control.
Rotate before revoking
Create a replacement key first, update the integration, and verify its requests succeed. Then revoke the old key. Revocation is immediate and irreversible; integrations still using it fail on their next request.
Where you are now
Your integration has a separately manageable, organization-scoped credential with clear attribution and permissions.
WHEN SOMETHING LOOKS OFF
A few things to check
The secret was lost
Create a replacement; an existing secret cannot be revealed again.
A write-capable key cannot read data
Write does not include read. Grant the required read scope explicitly.
PUT IT INTO PRACTICE
Make your next move in Secorvia.
Open the app and follow along with your own organization.