Members & API keys
Keys for your systems and read-only keys for auditors, with scope, expiry and an access log.
Steps
1. Choose the role and, for an auditor, the scope and expiry2. Click "Create key" and copy it (shown once)3. Hand it over safely; revoke it here when it is no longer needed
Create a key
Keys are for systems, not for people. People sign in with a passkey (the Members tab). An administrator key is what your platform's backend uses to call the API. An auditor key is read-only: it cannot verify, grant, revoke or approve anything, it sees only the principal and period you allow, it expires, and every request made with it is written to an access log you can show the regulator. Keys are stored hashed; nobody, not even Mandatary.ai, can read one back.
Keys
Loading…