# API keys

> Scoped, revocable keys for machine access to your company data. Shown once, stored only as a hash, and never able to reach settings, people or security.

Section: API, webhooks and security · Canonical: https://intubu.intuitivecapital-dai.com/docs/api-keys

Settings → API & Webhooks → *API keys*. Creating and revoking keys needs a company administrator (or the *api.keys.manage* permission).

**How do I create a key?** *New key*, give it a name (so you know what to revoke later), tick its scopes and optionally an expiry date, then *Create key*. A key needs at least one scope.

**The scopes** are read or write per area: `read:accounting` / `write:accounting`, `read:sales` / `write:sales`, `read:purchases` / `write:purchases`, `read:banking` / `write:banking`, `read:inventory` / `write:inventory`, `read:projects` / `write:projects`, and read-only `read:reports`, `read:taxes` and `read:payroll`. A write scope includes the matching read. Reports, taxes and payroll cannot be changed through the API at all.

**The key is shown exactly once.** Only a SHA-256 hash is stored, so a database leak cannot be replayed against your account — and it also means nobody can show it to you again. If you lose it, revoke it and issue another.

**Using it:** send it in the Authorization header as the word Bearer followed by the key (it starts `lp_`). A key belongs to one company, so no company header is needed. To read your books into Excel, Power BI or Tableau, the same key is the password — see [A live link to Excel, Power BI or Tableau (OData)](https://intubu.intuitivecapital-dai.com/docs/excel-bi-odata).

**What a key can never reach.** Keys reach company data only — accounting, sales, purchases, banking, inventory, projects, reports, taxes and payroll. Settings, people and roles, security, integrations, mail, text messages, other API keys and webhooks are refused, so a key cannot make another key or change who has access. A key also never does more than the person who created it: narrow that person's role, or deactivate them, and their keys narrow or stop with it.

**Limits.** Each key may make 3,000 requests in ten minutes; past that it is paused for ten minutes.

**Revoking** takes effect immediately; a revoked key stays in the list marked *Revoked*.

Every key records when it was last used and how many requests it has made, so an unused key is easy to spot and retire.

**One detail for integrators.** An unknown path under /api answers with the same JSON error envelope as every other error (ERR-GEN-001 with the method and path), never an HTML page.
