Skip to main content

API keys

This guide covers managing your organization's API keys on the portal's API keys page: copying, revealing, and rotating them. How keys authenticate code against the API is covered in Authentication.

Every organization gets exactly two keys — there is no create form and no key list. Each key has one job:

KeyPrefixJobWhen you rotate it
Mobile SDK Integration Keyopl_sdk_…Initializes the OptoLink SDK in your iOS, Android, or Flutter appOld key keeps working for 24 hours
Server API Keyopl_api_…Authenticates your backend against the link-management REST API — the Node SDK is one client of it, but any HTTP client works (curl, Python, PHP, …)Old key stops working immediately

Every org member can view the page. Regenerate buttons appear only for Developer role and above.

Open the API keys page​

Open API keys in the portal sidebar. You see two key cards, each with a "Generated" date in its footer.

If your plan doesn't include API access — it unlocks on Growth and above, see Plans & pricing — the page shows an upgrade banner and two locked cards instead of keys. Upgrade takes you to the billing page; until you upgrade, regenerating fails with "API access is not available on your plan".

The server key's whole surface is link management: create, list, update, delete, and QR codes through the /links REST endpoints. The same plan rules apply as in the portal — your org must have a registered app config, and the plan's link quota holds. Full endpoint reference in Link management API.

Copy a key​

  • The Mobile SDK Integration Key is shown in full on its card. Click Copy.
  • The Server API Key is masked as opl_api_••••••••. Copy still copies the real key — masked or revealed, the clipboard gets the full key.

Reveal the server key​

Click the eye icon on the Server API Key card to unmask it. The reveal lasts only while the page stays open — reload, and the key is masked again. The SDK key needs no reveal; it is always visible.

Rotate a key​

  1. Click Regenerate on the card you want to replace.
  2. The confirmation dialog states what happens to the old key:
    • SDK key: "The old key stays valid for 24 hours, so app versions already shipped keep working…"
    • Server key: "The old key stops working immediately. Any service still using it will lose access right away."
  3. Confirm. A toast reads "API key regenerated" and the card now holds the new key.

Before rotating the server key, update every service that uses it — there is no grace period.

You can regenerate up to 5 times per hour. Past that you get "Too many regenerations — try again later".

If a key card is masked with a hint​

Cards left over from the older key format show a dashed masked row with the hint "Regenerate this key once to make it visible here." Regenerate once and the card behaves normally from then on.