View API Credentials
APIs & Services provides self-service management for Client IDs and secrets used with Somos® API Gateway at api.somos.com for users with permissions to access this feature.
Select the APIs & Services menu item from the left side navigation. Select the Tenant and, when needed, a Product filter. Review the following:
-
Active API Credentials:
- Labels
- Client ID
- Secret
- Roles
- Created By
- Created Date
- Last-Used
Create an API Credential
Each credential should have a label that makes its business or integration purpose easy to recognize. When credentials need access only to a particular product and role, selecting those values limits its reach.
A global credential should be created only when broader access is appropriate and authorized.
Select the Add Credentials button. Within the Add API Credentials pop-up window, enter a label that identifies the credential purpose. Optionally select a product and role to restrict the credentials. Leave them unselected only when a global credential is appropriate and permitted.
Select the Plus (+) icon if another permitted product and role assignment is required. Select the Add Credential button. Confirm the success message, then securely copy and store the Client ID and secret.
You will see a Success message in the upper right corner on the API & Services page when the changes have been saved successfully. After that message has appeared, securely copy and store the Client ID and secret. Ensure that the Client ID and secret are stored in the organization's approved secret-management location. The credential then appears in the active list, where its role assignments and usage information can be reviewed.
Revoke an API Credential
Revocation permanently stops an active credential from authenticating to the API. Before revoking it, identify the integration that uses the credential and be prepared to replace its configuration if service must continue.
Retrieve the existing API Credential on the APIs & Services page. Select the Revoke button. A pop-up message will appear. In the pop-up window, please review the confirmation message and select the Revoke button again. Update any integration that uses the credentials. A revoked credential cannot be used to go forward.