Limited Permission API Key

Comments

4 comments

  • Dave Murphy

    Thanks Matt.  Makes a ton of sense as we continue to enhance our capabilities for larger teams.

    0
    Comment actions Permalink
  • Nikhil Karkera

    Dave, just to confirm my understanding here - you are saying that Split.io cannot provide this type of an API key currently?

    So the only types of API keys are:
    1) read-only
    2) full-access to everything, and all operations (create, read, update, delete)

    ?

    0
    Comment actions Permalink
  • Dave Murphy

    Hi Nikhil, yes the Admin API has full access.  The SDK/browser APIs are read only in that they can only send impressions.  They can't change splits or segments, etc.  Make sense?

    0
    Comment actions Permalink
  • Lars Rothberg-hansen

    +1 from here. In addition to that, locking an API key to an environment.

    I was going to do some tooling as I am not that keen on giving full access to the admin UI, but not really sure if I want to go ahead, it's not ideal to have a full admin key floating around internally.

    0
    Comment actions Permalink

Please sign in to leave a comment.