Skip to content
Developer Resources

API - Security Initiatives

TABLE OF CONTENTS Auto-deletion of API keys after 90 days of inactivity Auto-deletion of API keys after 90 days of inactivity Agency or sub-account API…

1 min read244 words2 explained imagesUpdated Wed, 24 Jun at 10:35 PM
View as markdownOpen in ClaudeOpen in ChatGPT
Each image has a one line explanation. Switch to full detail for the step it belongs to, the fields and buttons involved, examples and the whole procedure.

TABLE OF CONTENTS

Auto-deletion of API keys after 90 days of inactivity

  • Agency or sub-account API keys that have not been used in the past 90 days will be automatically deleted.
  • Deletion cadence: This activity will be once a quarter (automated) across all agency and sub-account API keys.
  • Customer communication:
    • The impacted Agency and Sub-accounts admins will receive three in-app notifications giving them a heads-up - 15 days, 7 days, and 1 day before the deletion
    • Agency admins (included those whose locations are impacted) will receive an email 15 days prior with a complete summary of the upcoming deletion
    • One day before the deletion, for 24 hours, the impacted agencies and sub-accounts will see a banner informing them about the upcoming deletion.

Inactive Legacy API Keys Expire After 90 Days

Inactive legacy API keys are now marked as Expired after 90 days of inactivity to reduce unnecessary credential exposure and improve account security.

This applies to both:

  • Agency-level legacy API keys
  • Location-level legacy API keys

Important:

Active keys are not affected

Expired keys remain visible in settings

If access is still needed, an expired key can be used again after it is rotated or refreshed

New v1 API key creation is no longer supported

Private Integration Tokens (PIT) are the recommended option for any new credentials

Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity.

Inactive Legacy API Keys Expire After 90 Days (image 1 of 2) What this shows Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity. What this shows Illustrates the "Inactive Legacy API Keys Expire After 90 Days" section of "API - Security Initiatives". This screenshot appears in the "Inactive Legacy API Keys Expire After 90 Days" section of "API - Security Initiatives". The text alongside this image reads: Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity. This part of the guide covers 2 fields, listed below. Image 1 of 2 What this coversUsers may also receive email notifications when a legacy API key is approaching expiration due to inactivity.
Fields in this part of the guide Agency-level legacy API keysLocation-level legacy API keys
Buttons and menus referenced Expiredrotatedrefreshedv1 API key creationPrivate Integration Tokens (PIT)
All 2 steps in this procedure
  1. Agency-level legacy API keys
  2. Location-level legacy API keys
Inactive Legacy API Keys Expire After 90 Days (image 2 of 2) What this shows Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity. What this shows Illustrates the "Inactive Legacy API Keys Expire After 90 Days" section of "API - Security Initiatives". This screenshot appears in the "Inactive Legacy API Keys Expire After 90 Days" section of "API - Security Initiatives". The text alongside this image reads: Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity. This part of the guide covers 2 fields, listed below. Image 2 of 2 What this coversUsers may also receive email notifications when a legacy API key is approaching expiration due to inactivity.
Fields in this part of the guide Agency-level legacy API keysLocation-level legacy API keys
Buttons and menus referenced Expiredrotatedrefreshedv1 API key creationPrivate Integration Tokens (PIT)
All 2 steps in this procedure
  1. Agency-level legacy API keys
  2. Location-level legacy API keys

Was this guide helpful?

Related guides