Skip to content
  • api
  • dashboard

Give an API key access to only what it needs

Create a restricted API key limited to the resources you pick, each at read or write. Every key is also capped by its owner's current role.

Create an API key that can only do what its job needs. A key for your checkout service can send email and read templates, and nothing else, so a leaked key has a small blast radius.

await samva.apiKeys.create({
  name: "Transactional sender",
  access: { mode: "restricted", resources: { messages: "write", templates: "read" } },
});

Every key is also capped by its owner's current role. Demote the owner and the key loses that access on the next request; remove the owner and the key stops working.

Authentication lists the resources you can grant.