API keys

Issue and rotate API credentials for approved integrations.

Institution administrators can manage API access while keeping credentials scoped, hashed, and auditable.

Page focus

Key areas

Scoped issuance

Only authorized institution roles create credentials for approved integration use cases.

Protected storage

Created credentials are shown once and retained only as protected validation records.

Rotation and revocation

Replace credentials without losing access history or audit evidence.

Governed by design

Designed for responsible credit workflows

Production credential control

API keys are treated as sensitive access, not casual configuration.

Backend-only use

Keys belong in approved server systems, never public browser code.

Access review

Creation, use, and revocation events support security review.

Next step

Bring this workflow into your institution.

Use the public route to orient teams, then configure the private portal and API workflows around your approved policy.

Contact DurujScore