A key is how a website proves it is yours. It lives on Agency Partners → Website & API in your account.
One key per site
Give each key the name of the site it is for. Five may be active at a time, which covers your sites plus a staging copy. Sharing one key between two sites works and is a bad idea: you then cannot tell which site did what, and cannot revoke one without breaking the other.
What a key can and cannot do
| Can | Cannot |
|---|---|
| Read your catalogue and your prices | Pay for anything |
| Check whether a domain is free | See your invoices or your payment methods |
| Create clients and place orders in your space | Change your plan, your details or your other keys |
| Read back the orders it placed | Reach another agency's clients or orders |
There is no payment endpoint behind a key at all. That is the reason a stolen key costs you a cancelled order rather than money.
What the page tells you
Each key shows its name, its first characters, the website that last used it, when that was and how many calls it has made. That is enough to recognise a key you no longer want, and it is all we can show: we store a one-way hash of the key, so nobody here — including us — can read one back.
Revoking
Click Revoke beside the key. From that moment anything still using it is refused, and the site that was using it says so on its dashboard.
The row stays on the page, marked revoked, with the usage it had. That is on purpose: after a key has been revoked is exactly when you want to know what it had been doing.
Important
Revoke a key whenever you have any doubt about it — a laptop lost, a contractor leaving, a site handed over. Creating a replacement takes seconds and the only thing to do afterwards is paste the new one into that site.
If you lose a key
There is nothing to recover. Revoke it and create another. Your products, your prices, your clients and your orders are untouched by the change — the key is a credential, not a container.
When you remove the plugin
Uninstalling removes the plugin's settings from WordPress, key included. Revoke that key here as well: nothing should hold a credential that no longer has a use.