Skip to navigationSkip to main contentSkip to footerScaleway Docs HomepageAsk our AI
Ask our AI

How to create API keys

API keys are unique identifiers necessary to use the Scaleway API (External link). You generate them via the Scaleway console, either for your own IAM user or for an IAM application.

An API key inherits the permissions of its bearer, which is the IAM user or IAM application it is associated with. The key grants exactly the rights defined for that bearer in the Organization via policies.

Each API key is scoped to a single Organization. If you belong to several Organizations, you need a separate API key for each one. A user or application can hold multiple API keys within the same Organization.

You can generate API keys for your own user, but not for other IAM users, regardless of your permissions. To generate API keys for an IAM application, you must be the Organization Owner or have the IAMManager or IAMApplicationManager permissions.

API keys attached to your own user are suitable for testing and accessing your infrastructure. For long-lived keys, such as those used in production, Scaleway recommends using an IAM application as the bearer. Because applications are non-human users, their API keys are not affected if a member leaves or is removed from the Organization.

Before you start

To complete the actions presented below, you must have:

  1. Click IAM & API keys on the top-right drop-down menu of the Scaleway console. You are taken to your Identity and Access Management dashboard (External link).

  2. Click the API keys tab.

  3. Click + Generate API key. The following screen pops up:

  4. Select the bearer of the API key. Choose between yourself (as an IAM user), or an IAM application associated with the Organization.

  5. Enter an optional description for the API key.

  6. Enter the desired expiration. Choose from:

    • Never: the API key will never expire,
    • 1 hour / week / month / year: the API key will expire at the end of the selected period,
    • Custom: you are prompted to enter a date on which the API key will expire.
  7. Select whether the API key will be used for Object Storage. Choose from:

    • Yes, set up preferred Project: you are prompted to select a Project that the API key will always use for Object Storage operations.
    • No, skip for now: the Project that you are currently navigating in the console (i.e. the one that is selected in your Project dashboard) will be automatically selected as the preferred Project for Object Storage.
    Note

    Preferred Projects for Object Storage - When creating and/or listing Object Storage buckets via the API, there is no available parameter to specify the Project in which you wish to list or create buckets. All buckets you create via the API will therefore be created in the preferred Project you choose when creating the API key. Similarly, when listing buckets, buckets from your preferred Project will be listed. Note that:

    • This applies to all actions on Object Storage buckets, but it does not apply to other products or resources.
    • You can still create and/or list buckets in your Project of choice via the Scaleway console. See our dedicated documentation for more information.
  8. Click Generate API key. A screen displays showing the access key and secret key for your new API key and reminding you that this is your only chance to securely save the secret key.

  9. Ensure you have securely saved the secret key, then close the window. You are returned to the API keys tab, where your new API key now appears in the list.

Still need help?

Create a support ticket
No Results