Partner integrations authenticate with an API key scoped to your business.
Create a key
- Open API keys in settings.
- Create a key and copy the value immediately — Documate shows the secret only once.
- Store it in your secret manager. Never commit keys to source control.
Use the key
Send the key on every External API request:
You can also send Authorization: ApiKey YOUR_API_KEY.
Revoke
Revoke a key from the same page when it is compromised or unused. Create a replacement key before revoking a key that production systems still call.
Treat API keys like passwords. Anyone with a key can upload and read data for that business.