Billing, Settings & Developer API
Create and protect API keys
Create a Business-scoped server credential, copy the full secret once, optionally expire it, and revoke it immediately if exposed.
Overview
- Only Owners and Business Managers can manage Business API keys.
- Creating a key requires API Access to be enabled for the Business.
- A new key has a recognisable Name, selected scopes, and an optional expiration timestamp.
- MiniTill stores a SHA-256 hash of the secret and only retains/displays a short prefix for identification.
- The full secret is shown exactly once immediately after creation. After leaving that screen MiniTill cannot display the full value again.
- Production keys use an sp_live_ prefix; non-production environments use sp_test_.
- Revoking a key marks it inactive and future authentication with that key fails.
When to use this
- Create one key per external integration/service so access can be identified and revoked independently.
Step-by-step
- Open Settings → Developer / API → API Keys.
- Choose Create API key.
- Give it a specific name such as 'Accounting data warehouse'.
- Set an expiry if appropriate.
- Choose only the required scopes.
- Create and copy/store the full secret immediately.
- Use Last used, Expiry, Prefix, and Status to maintain credentials.
- Revoke a key as soon as it is no longer required or may have leaked.
Common mistakes
- Do not leave the one-time secret screen before securely storing the key.
- Do not share one powerful key across unrelated integrations.
- Do not log the full API key in application logs, analytics, support tickets, or source control.
Troubleshooting
- If the full key was lost, create a replacement key and revoke the old one; MiniTill cannot recover the stored secret from its hash.
- If a key stopped working, check Active status, Expiry, Business status, API entitlement, and scopes.