Skip to main content
An API key connects a backend to one NBQ and a precise set of permissions. Complete secrets are displayed only when created.
Placeholder for the final API Keys page screenshot

Recommendation

Create at least:
  • one runtime key per environment for conversations;
  • a separate management key only if you automate configuration;
  • no public key in a browser or mobile application.
The list displays only a masked form, final characters, status, and non-sensitive metadata. Revocation immediately blocks new calls.

Secure an API key

Review storage, rotation, and exposure-response practices.