- Key ID (
ok_…) — the public name of the key. Visible any time. Safe to write in logs and support tickets. It identifies the key and cannot call the API. - Secret (
osk_…) — the credential. Shown exactly once, right after the key is created. orriven stores only a hash. A lost secret cannot be recovered. Generate a new key and revoke the old one.
opk_…) — credential for the Storefront API — is a single token that is public by design. It ships in frontend code and serves the Business Unit’s public storefront (catalog, redemption-code lookup, checkout sessions). It has no secret half. It appears in full in the key list at any time. Creating one adds one field:
- Allowed origins — exact origins (
https://tickets.example.com) the site runs on. Browser requests from anywhere else are refused. Origins can be edited later, so a domain change does not require rotating a key embedded in a deployed frontend.
401.
Who can manage keys
Only organization Owners and Admins can view, generate, or revoke keys. Planners and other roles do not have access. A key’s reach is broader than those roles, so issuing one is an administrator decision.Generating a key
1
Open API keys and choose Generate key
Name the key after the integration — “CRM sync”, “check-in kiosk”. The name is for bookkeeping.
2
Copy the secret from the banner
The full secret appears once in a banner with a copy button. The banner cannot be dismissed for a few seconds. After leaving the page, only the prefix (
osk_1a2b…) remains visible.3
Call the API
Send the secret as a bearer token on every request:
The key list
Keys are listed in two sections, one per kind. The secret-key list shows name, Key ID, secret prefix, pinned API version, last used, and status: Active, Revoked, or Expired. The publishable-key list shows the full, copyableopk_ token and its allowed origins (editable in place). “Last used” updates as the integration calls the API. A key that still shows Never after deployment is not reaching orriven.
Revoking
Revoking a key takes effect immediately. Every request using it starts failing with the same401 an unknown key gets. Revocation cannot be undone. Revoked keys stay in the list as a record. To rotate a credential, generate the new key first, switch the integration, then revoke the old one.
Rules
- The secret appears once. Not in the list, not in any API response, not to support. Lost secret = new key.
- One key, one Business Unit. A key never sees another unit’s data. A request for another unit’s event is treated as if the event did not exist.
- All key activity is audited. Generation and revocation appear in the audit log. Every write the key performs is recorded with the key as the actor.
- Invalid means invalid. A missing, mistyped, revoked, or expired secret all produce the same
401. The response does not reveal whether a credential once existed.
Related
Quickstart
First calls with a new key.
Command-line tool
Generate and revoke keys from the terminal.
Agents
Automate API key management using the Model Context Protocol (MCP) server.
Members & roles
Why key management is Owner/Admin only.