Skip to main content
The API keys page is on Business Unit navigation, between Members and Settings. There are two kinds of key. A secret key — credential for the Developer API — is a pair:
  • Key ID (ok_…) — the public name of the key. Visible any time. Safe to write in logs and support tickets. It identifies the key and cannot call the API.
  • Secret (osk_…) — the credential. Shown exactly once, right after the key is created. orriven stores only a hash. A lost secret cannot be recovered. Generate a new key and revoke the old one.
A secret key can read and write everything in its Business Unit. Keep the secret in a server-side secret store. Do not put it in a browser, a mobile app, or a repository.
A publishable key (opk_…) — credential for the Storefront API — is a single token that is public by design. It ships in frontend code and serves the Business Unit’s public storefront (catalog, redemption-code lookup, checkout sessions). It has no secret half. It appears in full in the key list at any time. Creating one adds one field:
  • Allowed origins — exact origins (https://tickets.example.com) the site runs on. Browser requests from anywhere else are refused. Origins can be edited later, so a domain change does not require rotating a key embedded in a deployed frontend.
The two kinds are mutually exclusive on the wire. Each authenticates only on its own surface. Presenting one where the other belongs returns 401.

Who can manage keys

Only organization Owners and Admins can view, generate, or revoke keys. Planners and other roles do not have access. A key’s reach is broader than those roles, so issuing one is an administrator decision.

Generating a key

1

Open API keys and choose Generate key

Name the key after the integration — “CRM sync”, “check-in kiosk”. The name is for bookkeeping.
2

Copy the secret from the banner

The full secret appears once in a banner with a copy button. The banner cannot be dismissed for a few seconds. After leaving the page, only the prefix (osk_1a2b…) remains visible.
3

Call the API

Send the secret as a bearer token on every request:

The key list

Keys are listed in two sections, one per kind. The secret-key list shows name, Key ID, secret prefix, pinned API version, last used, and status: Active, Revoked, or Expired. The publishable-key list shows the full, copyable opk_ token and its allowed origins (editable in place). “Last used” updates as the integration calls the API. A key that still shows Never after deployment is not reaching orriven.

Revoking

Revoking a key takes effect immediately. Every request using it starts failing with the same 401 an unknown key gets. Revocation cannot be undone. Revoked keys stay in the list as a record. To rotate a credential, generate the new key first, switch the integration, then revoke the old one.

Rules

  • The secret appears once. Not in the list, not in any API response, not to support. Lost secret = new key.
  • One key, one Business Unit. A key never sees another unit’s data. A request for another unit’s event is treated as if the event did not exist.
  • All key activity is audited. Generation and revocation appear in the audit log. Every write the key performs is recorded with the key as the actor.
  • Invalid means invalid. A missing, mistyped, revoked, or expired secret all produce the same 401. The response does not reveal whether a credential once existed.

Quickstart

First calls with a new key.

Command-line tool

Generate and revoke keys from the terminal.

Agents

Automate API key management using the Model Context Protocol (MCP) server.

Members & roles

Why key management is Owner/Admin only.