API keys allow you to authenticate with the Vibe OnCall Public API and integrate with external systems without relying on user sessions. Each key is scoped to your organization and should be treated as a secret credential.


Who Can Manage API Keys

The API Keys page is available to roles that hold the Manage API keys permission. Members without it don't see the page. Grant it from Administration → Roles when you want someone other than an admin to create, edit, or revoke keys (See Roles and permissions ).


Creating an API Key

  1. Navigate to Administration → API Keys.
  2. Click Create API Key.
  3. Enter a descriptive Name that identifies the integration this key will be used for (e.g., CI/CD Pipeline, Monitoring Script). Optionally add a Description of what the key is for.
  4. Choose an Expiration — 7 days, 30 days, 90 days, 1 year, a Custom date, or No expiration. An expiring key stops authenticating at the end of that day.
  5. Choose an Access level — Full access, Read-only, or Custom. You must pick one; see Choosing What a Key Can Do below.
  6. Click Create API Key and copy the key immediately — it is displayed only once and cannot be retrieved after you close the dialog.

API keys use the format vlk_ followed by 40 hex characters (e.g., vlk_a1b2c3d4e5f6...).

Screenshot 2026-09-30 at 3.50.25 PM.png


Choosing What a Key Can Do

Every key has an Access level that limits what it can do. Give each integration only the access it needs.

Access What the key can do
Full access View data and make any change, including in features we add later.
Read-only View data only. It can't make changes or ping heartbeats.
Custom View data, and make only the changes you choose. Select at least one action, such as commenting on incidents or Ping heartbeats.

Using an API Key