Create
Settings → API keys → New key. Pick a name, the apps it may touch, and an expiry. The secret is shown once.
One key, three layers of permission. Everything the key can do is exactly what its owner could do in the UI — nothing more.
Settings → API keys → New key. Pick a name, the apps it may touch, and an expiry. The secret is shown once.
Rotate any key with zero downtime: the old secret stays valid for a 24-hour grace period while you deploy the new one.
Revoke instantly from the same page. In-flight requests finish; new requests get 401 immediately.
Every request carries Authorization: Bearer <key>. The gateway binds the key to its user (user_id + organization_id) and injects the permission context into the request — no per-call identity parameters needed.
curl https://api.bodegito.com/v1/oms/orders?page_size=5 \
-H "Authorization: Bearer $BODEGITO_API_KEY"Keys inherit the owner's three layers: app access (which of the six apps), feature permissions (read vs write per module), and data scope (warehouses, merchants). A 403 means the key — like its owner — is not allowed there.
Pin a key to specific egress IPs for extra safety. Coming soon — the API surface is ready, the UI is not.