MTMini Till
← Back to Help Centre

Billing, Settings & Developer API

Create and protect API keys

Create a Business-scoped server credential, copy the full secret once, optionally expire it, and revoke it immediately if exposed.

Overview

  • Only Owners and Business Managers can manage Business API keys.
  • Creating a key requires API Access to be enabled for the Business.
  • A new key has a recognisable Name, selected scopes, and an optional expiration timestamp.
  • MiniTill stores a SHA-256 hash of the secret and only retains/displays a short prefix for identification.
  • The full secret is shown exactly once immediately after creation. After leaving that screen MiniTill cannot display the full value again.
  • Production keys use an sp_live_ prefix; non-production environments use sp_test_.
  • Revoking a key marks it inactive and future authentication with that key fails.

When to use this

  • Create one key per external integration/service so access can be identified and revoked independently.

Step-by-step

  1. Open Settings → Developer / API → API Keys.
  2. Choose Create API key.
  3. Give it a specific name such as 'Accounting data warehouse'.
  4. Set an expiry if appropriate.
  5. Choose only the required scopes.
  6. Create and copy/store the full secret immediately.
  7. Use Last used, Expiry, Prefix, and Status to maintain credentials.
  8. Revoke a key as soon as it is no longer required or may have leaked.

Common mistakes

  • Do not leave the one-time secret screen before securely storing the key.
  • Do not share one powerful key across unrelated integrations.
  • Do not log the full API key in application logs, analytics, support tickets, or source control.

Troubleshooting

  • If the full key was lost, create a replacement key and revoke the old one; MiniTill cannot recover the stored secret from its hash.
  • If a key stopped working, check Active status, Expiry, Business status, API entitlement, and scopes.