Consumers and API keys
Register a machine client, grant artifacts, rotate the key.
A consumer is a machine client that calls published Experience paths with X-API-KEY. Partners never self-register.
Steps (operator)
- Open Portal Consumers.
- Create a consumer with a descriptive name (for example
growth-os-bi). - Assign grants for the catalog artifacts the client needs (
contact-leads, …). - Copy the API key once. Rotate if compromised.
curl -sS \
-H "X-API-KEY: $CONNECT_API_KEY" \
"https://connect.intronsoft.com/api/v1/leads?limit=10"A key without the contact-leads grant receives 403 on /api/v1/leads.
Operations
| Action | Who |
|---|---|
| List | Developer+ |
| Create | Operator, Admin |
| Rotate key | Admin |
| Revoke | Admin |
Connect does not mint OAuth clients. Store the caller’s existing client id if you also track OIDC. Hashed keys live on catalog_consumer. Env CONNECT_API_KEYS is a laptop fallback.
Try it
APIs → System → Consumers (SSO in production).
If this fails
| Symptom | Cause |
|---|---|
| 403 with a valid key | Grant list does not include the artifact |
| Lost plaintext | Expected after the flash — rotate |
Next: Authentication