API Keys

An APIKey is a key that allows programmatic access to your Site.

API keys use the owning user's permissions, narrowed by the key's permission set, workspace scope, and any folder path restriction. If an API key is created without a user owner, it is considered a site-wide API key. Site-wide API keys with the files_only permission set are restricted to file-user permissions and workspace scoping.

Set path when creating a key to limit file and folder access to that folder and its descendants. Except for office_integration keys, the path does not need to exist when the key is created. The restriction applies to the files, folders, and file_actions endpoints, on every path those requests access, including both source and destination paths for copy and move operations. Requests to those endpoints outside the restriction are denied with not-authorized/api-key-is-path-restricted. It never grants additional access to the owning user. A key with the files_only permission set can use only those endpoints, plus GET /file_migrations/{id} to follow file operations under the visibility rules below and GET /api_key to read its own record. Every other endpoint denies a files_only key with not-authorized/api-key-only-for-file-operations.

On GET /file_migrations/{id}, any key with a path can read only migrations it started. Without a path, user-owned keys retain their user-scoped access, including Desktop and Mobile keys in the owning user's Workspace. A site-wide key bound to a Workspace can read a migration only when its source and destination are both in that Workspace. Workspace binding applies to every files_only key, including Workspace 0, and to full-access keys in a named Workspace. A full-access site-wide key in the default Workspace can read migrations across the Site. Migrations outside the caller's visibility return not-found.

We recommend registering API keys to service users wherever possible and then using User or Group Permissions to restrict that API Key appropriately.

Resource Schema

Required

PropertyDescription
name
String
Internal name for the API Key. For your use.

Optional

PropertyDescription
description
String
User-supplied description of API key.
expires_at
String
API Key expiration date
aws_style_credentials
Bool
If true, this API key will be usable with AWS-compatible endpoints, such as our Inbound S3-compatible endpoint.
permission_set
String
Permissions for this API Key. Keys with the desktop_app permission set only have the ability to do the functions provided in our Desktop App (File and Share Link operations). Keys with the office_integration permission set are auto generated, and automatically expire, to allow users to interact with office integration platforms. Keys with the files_only permission set can use only the files, folders, and file_actions endpoints, where they perform file operations as a full-access file user in the key's workspace scope, along with GET /file_migrations/{id} and GET /api_key. On the migration lookup, any key with a path can read only migrations it started. Without a path, user-owned keys retain user-scoped access; site-wide Workspace-bound keys can read only migrations whose source and destination are both in their Workspace. Every files_only key is Workspace-bound, including Workspace 0, as is a full-access key in a named Workspace. A full-access site-wide key in the default Workspace retains Site-wide migration access. Migrations outside the caller's visibility return not-found. Keys with files_only cannot use site admin, workspace admin, folder admin, group admin, partner admin, or billing privileges from the owning user, and every other endpoint denies them with not-authorized/api-key-only-for-file-operations.
Possible values: none, full, desktop_app, sync_app, office_integration, mobile_app, files_only
user_id
Int64
User ID for the owner of this API Key. May be blank for Site-wide API Keys.
workspace_id
Int64
Workspace ID for this API Key. 0 means the default workspace.
path
String
Restricts the file and folder operations made with this key, meaning the files, folders, and file_actions endpoints, to the specified folder and its descendants, including copy and move destinations. For GET /file_migrations/{id}, a key with a path can read only migrations it started. Other endpoints do not apply the path restriction; use the files_only permission set to confine a key to file operations and their supporting lookups. Does not grant access beyond the owning user's permissions. Optional except for office_integration keys, which require a path the owning user can read.

Read Only

PropertyDescription
id
Int64
API Key ID
descriptive_label
String
Unique label that describes this API key. Useful for external systems where you may have API keys from multiple accounts and want a human-readable label for each key.
created_at
String
Time which API Key was created
key
String
API Key actual key string
aws_access_key_id
String
AWS Access Key ID to use with AWS-compatible endpoints, such as our Inbound S3-compatible endpoint.
aws_secret_key
String
AWS Secret Key to use with AWS-compatible endpoints, such as our Inbound S3-compatible endpoint.
last_use_at
String
API Key last used - note this value is only updated once per 3 hour period, so the 'actual' time of last use may be up to 3 hours later than this timestamp.
platform
String
If this API key represents a Desktop app, what platform was it created on?
site_id
Int64
Site ID
site_name
String
Site Name
url
String
URL for API host.

Example Resource

resource "files_api_key" "example_api_key" {
  user_id               = 1
  description           = "example"
  expires_at            = "2000-01-01T01:00:00Z"
  name                  = "My Main API Key"
  aws_style_credentials = true
  path                  = "shared/docs"
  permission_set        = "full"
  workspace_id          = 1
}

Resource Import

This Resource supports importing using the following syntax:

Example Import Command

# Api Keys can be imported by specifying the id.
terraform import files_api_key.example_api_key 1

Data Source Schema

Required

PropertyDescription
id
Int64
API Key ID

Read Only

PropertyDescription
descriptive_label
String
Unique label that describes this API key. Useful for external systems where you may have API keys from multiple accounts and want a human-readable label for each key.
description
String
User-supplied description of API key.
created_at
String
Time which API Key was created
expires_at
String
API Key expiration date
key
String
API Key actual key string
aws_style_credentials
Bool
If true, this API key will be usable with AWS-compatible endpoints, such as our Inbound S3-compatible endpoint.
aws_access_key_id
String
AWS Access Key ID to use with AWS-compatible endpoints, such as our Inbound S3-compatible endpoint.
aws_secret_key
String
AWS Secret Key to use with AWS-compatible endpoints, such as our Inbound S3-compatible endpoint.
last_use_at
String
API Key last used - note this value is only updated once per 3 hour period, so the 'actual' time of last use may be up to 3 hours later than this timestamp.
name
String
Internal name for the API Key. For your use.
permission_set
String
Permissions for this API Key. Keys with the desktop_app permission set only have the ability to do the functions provided in our Desktop App (File and Share Link operations). Keys with the office_integration permission set are auto generated, and automatically expire, to allow users to interact with office integration platforms. Keys with the files_only permission set can use only the files, folders, and file_actions endpoints, where they perform file operations as a full-access file user in the key's workspace scope, along with GET /file_migrations/{id} and GET /api_key. On the migration lookup, any key with a path can read only migrations it started. Without a path, user-owned keys retain user-scoped access; site-wide Workspace-bound keys can read only migrations whose source and destination are both in their Workspace. Every files_only key is Workspace-bound, including Workspace 0, as is a full-access key in a named Workspace. A full-access site-wide key in the default Workspace retains Site-wide migration access. Migrations outside the caller's visibility return not-found. Keys with files_only cannot use site admin, workspace admin, folder admin, group admin, partner admin, or billing privileges from the owning user, and every other endpoint denies them with not-authorized/api-key-only-for-file-operations.
Possible values: none, full, desktop_app, sync_app, office_integration, mobile_app, files_only
platform
String
If this API key represents a Desktop app, what platform was it created on?
site_id
Int64
Site ID
site_name
String
Site Name
url
String
URL for API host.
user_id
Int64
User ID for the owner of this API Key. May be blank for Site-wide API Keys.
workspace_id
Int64
Workspace ID for this API Key. 0 means the default workspace.

Example Data Source

data "files_api_key" "example_api_key" {
  id = 1
}