API keys allow you to authenticate with the Vibe OnCall Public API and integrate with external systems without relying on user sessions. Each key is scoped to your organization and should be treated as a secret credential.
The API Keys page is available to roles that hold the Manage API keys permission. Members without it don't see the page. Grant it from Administration → Roles when you want someone other than an admin to create, edit, or revoke keys (See Roles and permissions ).
API keys use the format vlk_ followed by 40 hex characters (e.g., vlk_a1b2c3d4e5f6...).

Every key has an Access level that limits what it can do. Give each integration only the access it needs.
| Access | What the key can do |
|---|---|
| Full access | View data and make any change, including in features we add later. |
| Read-only | View data only. It can't make changes or ping heartbeats. |
| Custom | View data, and make only the changes you choose. Select at least one action, such as commenting on incidents or Ping heartbeats. |