Skip to main content
The API key enables you to directly use HiddenLayer’s API endpoints to get the full AI Security Platform experience.

Create API Key

  1. In the HiddenLayer Console, go to Settings > API Keys.
  2. Click + New.
    Create API Key button
  3. Enter a name for the API key, select an expiration, then click Next.
    Enter API Key Name
  4. Select the permissions for each category, then click Create API Key. You can select a combination of Read, Write, and Delete permissions, or click All to allow all permissions for the selected category. See the API Resources and API Permission Related to Products or Features tables below for more information.
    No Permissions SelectedNot selecting any permissions will create an API key with all permissions enabled.
    Select API Permissions
  5. A unique API key is generated. The clientID and clientSecret information is displayed. Click on the copy icon and save into a password manager or to a file in a secure location.
    Save the ID and SecretIt is important to save this information because you cannot retrieve it in the future.
    client ID and client Secret
  6. After saving this information, click Close.

Expired API Key

When an API key is created, an expiration is set. When an API key expires, it is securely deleted and automatically removed from the Console.

Delete API Key

  1. On the API Keys page, click the three vertical dots for the API key you want to delete.
    Select Action to Delete
  2. Click Delete. A message displays, asking you to confirm deleting the key.
    Message about Deleting Displays
  3. Click Delete.
    Deleting a Console user does not revoke that user’s API keys. If you are offboarding someone, delete their API keys as a separate step. See Access removal.

When should I create a new API key?

API keys are highly secure assets and should be treated as such. Below are examples of when new API keys need to be created. This list is provided as examples based on best practices, and is not exhaustive. We recommend reviewing your own company policies around such requirements.

API Resources

Some HiddenLayer products require an API key and secret. The following table lists all API permission categories and resources, along with the permissions needed for product deployments or features.
CategoryAPI PermissionNotes
AI PortfolioGeneral: Read, Write
Attack SimulationGeneral: Delete, Read, WritePermissions needed for AI Attack Simulation.
  • Read: Use any get or list API routes.
  • Write: Create a resource (e.g. start a Red Team Evaluation, create a Prompt Set).
  • Delete: Delete a resource.
ReportingReporting Aggregates: Read
Runtime SecurityConvictions: Read, Write
  • General: Delete, Read, Write
  • General Shared: Delete, Write
  • Interactions: Read, Write
  • Policy: Delete, Read, Write
  • Project: Delete, Read, Write

Permissions needed for AI Runtime Security: Interactions (Read, Write), Policy (Read), Project (Read).

Permissions needed for Interactions SaaS: Interactions (Read, Write).

Supply ChainGeneral: Delete, Read, Write
  • Scan Results: Write

Permissions needed for AI Supply Chain Security CLI Hybrid Mode, GitHub Action, and Azure DevOps Plugin: General (Read, Write), Scan Results (Write).

Hybrid Mode sends scan results to the AI Security Platform.

Tenant SettingsAPI Client Credentials: Delete, Read, Write
  • Audit Log: Read
  • General: Write
  • Integrations: Delete, Read, Write
  • Users: Delete, Read, Write

Permissions needed for Integrations and Single Sign-On (SSO): Integrations (Read, Write, Delete).

Prompt Analyzer (SaaS) only requires an API client ID and secret that are not expired.