Skip to content

Manage API keys

API keys authenticate calls made by an integrator to the Eveos public API. Each key carries a role, an optional project scope, and can be restricted, time-limited, monitored, and revoked.

  1. From a session, return to the organizer level: select “Events” in the breadcrumb at the top of the page, or “Switch Event” at the bottom of the sidebar.
  2. In the organizer sidebar, open “Settings” → “Developer” → “API Keys”.
  1. Select “Create key”.
  2. Enter a “Name” (e.g. “CRM integration”).
  3. Choose the “Role type”: a “System role” (Owner, Admin, User, Viewer, Onsite) or an existing “Custom role”.
  4. In “Projects”, leave empty to grant access to every project the role covers, or select specific projects.
  5. If needed, add “IP restrictions”: a single IP (203.0.113.7) or a CIDR range (203.0.113.0/24, IPv6 supported). Leave empty for no restriction.
  6. Optionally set an “Expiration date”; an expired key is automatically rejected at authentication.
  7. Select “Create”.

The integrator sends the key in one of these two headers:

X-Api-Key: evk_...

or

Authorization: Bearer evk_...

Whatever role is attached, an API key never accesses sensitive modules (users, integrations, communications, imports/exports…): the public API scope is limited to Projects, Sessions, Participants, Exhibitors, Checkins, Programs, and Orders (read-only).

A key can be Active, Revoked (manual, permanent, and immediate), or Expired (past its expiration date).

From a key’s action menu:

  • “Rotate” creates a new key with the same settings, then revokes the old one. The new secret is shown once, just like at creation.
  • “Revoke” disables the key immediately and permanently; it stays listed for audit purposes but no longer authenticates any call.

The “View usage” menu opens a detailed panel for a key:

  • Total calls and the last call details (date, HTTP status, route, source IP) over a 7, 14, or 30-day window.
  • Calls broken down by status class (2xx, 4xx, 429, 5xx).
  • A calls per day chart, with error counts on hover.
  • A top routes table (call count, average duration).