How to create API keys
API keys are unique identifiers necessary to use the Scaleway API (External link). You generate them via the Scaleway console, either for your own IAM user or for an IAM application.
An API key inherits the permissions of its bearer, which is the IAM user or IAM application it is associated with. The key grants exactly the rights defined for that bearer in the Organization via policies.
Each API key is scoped to a single Organization. If you belong to several Organizations, you need a separate API key for each one. A user or application can hold multiple API keys within the same Organization.
You can generate API keys for your own user, but not for other IAM users, regardless of your permissions. To generate API keys for an IAM application, you must be the Organization Owner or have the IAMManager or IAMApplicationManager permissions.
API keys attached to your own user are suitable for testing and accessing your infrastructure. For long-lived keys, such as those used in production, Scaleway recommends using an IAM application as the bearer. Because applications are non-human users, their API keys are not affected if a member leaves or is removed from the Organization.
Before you start
To complete the actions presented below, you must have:
- A Scaleway account logged into the console (External link)
-
Click IAM & API keys on the top-right drop-down menu of the Scaleway console. You are taken to your Identity and Access Management dashboard (External link).
-
Click the API keys tab.
-
Click + Generate API key. The following screen pops up:
-
Select the bearer of the API key. Choose between yourself (as an IAM user), or an IAM application associated with the Organization.
-
Enter an optional description for the API key.
-
Enter the desired expiration. Choose from:
- Never: the API key will never expire,
- 1 hour / week / month / year: the API key will expire at the end of the selected period,
- Custom: you are prompted to enter a date on which the API key will expire.
-
Select whether the API key will be used for Object Storage. Choose from:
- Yes, set up preferred Project: you are prompted to select a Project that the API key will always use for Object Storage operations.
- No, skip for now: the Project that you are currently navigating in the console (i.e. the one that is selected in your Project dashboard) will be automatically selected as the preferred Project for Object Storage.
-
Click Generate API key. A screen displays showing the access key and secret key for your new API key and reminding you that this is your only chance to securely save the secret key.
-
Ensure you have securely saved the secret key, then close the window. You are returned to the API keys tab, where your new API key now appears in the list.