The API Keys tab allows you to generate and revoke access keys for third-party integrations.
Navigation: Settings → Security & Access → API Keys
| Field | Description |
|---|---|
| Name | A descriptive name for identification (for example "ERP Integration") |
| User | The system user the key is issued for — required |
| Expiry (optional) | An optional expiry date; if left blank, the key does not expire automatically |
| Key | The access key — shown only at creation |
| Prefix | The first characters of the key, for identification in the list |
| Created | When (and by whom) the key was created |
| Expiry | The expiry date, if one was set |
| Last Used | When the key was last used |
| Status | Active or Revoked |
Click "Revoke" next to the key. This action is irreversible — integrations using this key will stop working immediately. A revoked key can then be permanently removed from the list with "Delete" — only a revoked key can be deleted.
Keys are shown only once at creation — copy and store securely.
The Lab Director (LAB_DIRECTOR) role is required to manage keys.