Team: Huntress Managed Endpoint Detection and Response
Product: Huntress Agent
Environment: Huntress portal
Summary: How to generate API Keys
How to Create an API Key
This guide walks you through creating a user-based API key in the Huntress Platform. API keys are essential for integrating Huntress with other tools and automating workflows.
Prerequisites
First determine what type of API key and permissions you need for your use case. It is recommended that you create a key with the least privileges needed to accomplish your goal.
User API Key (Recommended)
API keys associated with users mirror the permissions of the user. This allows for keys to be created for write APIs as well as used in read only use cases. Using this method multiple API keys can be created for a user and for an account.
Step-by-Step Instructions to Create a User API Key
- Log in to the Huntress Platform as a user with Admin privileges.
- In the hamburger menu in the upper right corner choose the API Credentials menu option.
- In the User API Credentials section click the Add button.
- The Create User API Credential window will appear. Select a user from the dropdown and provide a descriptive name for your key in the Key Name field (e.g., "Custom Integration").
- Click Add
- A new box will appear with the API Credentials. Copy the API Key and Secret and store in a secure location.
- Important: For security reasons, the full key is shown only once after creation. Huntress cannot retrieve this key if it is lost. If you lose the key, you will need to delete it and create a new one.
- Click the Ok button once the credentials have been copied. The key has been created and will now appear in the API Keys list on the My Settings page.
Account API Key (Deprecated)
Important: Account API keys are deprecated. They provide read-only access and do not provide access to all data available through the Huntress API. If you currently use an account API key, migrate to a user-based API key as soon as practical. You may receive permission denied or experience missing data in the API when using an account based API key.