Create API Key
- In the HiddenLayer Console, go to Settings > API Keys.
-
Click + New.

-
Enter a name for the API key, select an expiration, then click Next.

-
Select the permissions for each category, then click Create API Key. You can select a combination of Read, Write, and Delete permissions, or click All to allow all permissions for the selected category.
See the API Resources and API Permission Related to Products or Features tables below for more information.
No Permissions SelectedNot selecting any permissions will create an API key with all permissions enabled.

-
A unique API key is generated. The
clientIDandclientSecretinformation is displayed. Click on the copy icon and save into a password manager or to a file in a secure location.Save the ID and SecretIt is important to save this information because you cannot retrieve it in the future.
- After saving this information, click Close.
Expired API Key
When an API key is created, an expiration is set. When an API key expires, it is securely deleted and automatically removed from the Console.Delete API Key
-
On the API Keys page, click the three vertical dots for the API key you want to delete.

-
Click Delete. A message displays, asking you to confirm deleting the key.

-
Click Delete.
Deleting a Console user does not revoke that user’s API keys. If you are offboarding someone, delete their API keys as a separate step. See Access removal.
When should I create a new API key?
API keys are highly secure assets and should be treated as such. Below are examples of when new API keys need to be created. This list is provided as examples based on best practices, and is not exhaustive. We recommend reviewing your own company policies around such requirements.API Resources
API Permission Related to Products or Features
Some HiddenLayer products require an API key and secret. The following table lists all API permission categories and resources, along with the permissions needed for product deployments or features.| Category | API Permission | Notes |
|---|---|---|
| AI Portfolio | General: Read, Write | |
| Attack Simulation | General: Delete, Read, Write | Permissions needed for AI Attack Simulation.
|
| Reporting | Reporting Aggregates: Read | |
| Runtime Security | Convictions: Read, Write
| Permissions needed for AI Runtime Security: Interactions (Read, Write), Policy (Read), Project (Read). Permissions needed for Interactions SaaS: Interactions (Read, Write). |
| Supply Chain | General: Delete, Read, Write
| Permissions needed for AI Supply Chain Security CLI Hybrid Mode, GitHub Action, and Azure DevOps Plugin: General (Read, Write), Scan Results (Write). Hybrid Mode sends scan results to the AI Security Platform. |
| Tenant Settings | API Client Credentials: Delete, Read, Write
| Permissions needed for Integrations and Single Sign-On (SSO): Integrations (Read, Write, Delete). Prompt Analyzer (SaaS) only requires an API client ID and secret that are not expired. |

