DOCS · API KEY MANAGEMENT
API Key Management
UPDATED 22 NOVEMBER 2025
Secure generation, storage, and lifecycle management of API keys.
Generating API Keys
In Merchant Dashboard:
Navigate to Settings → API Access
Click "Generate New API Key"
Enter key name (e.g., "Production Dashboard")
Select permissions (currently all or none)
Copy and store securely (shown only once)
API Key Security
Storage Best Practices:
❌ Never Do This:
// DON'T hardcode in source code
const API_KEY = 'aiva_live_abc123xyz456';
// DON'T commit to Git
// .env file committed to repository
// DON'T expose in frontend
const apiKey = 'aiva_live_abc123xyz456';
✅ Do This:
# Store in environment variables
export AIVA_API_KEY=aiva_live_abc123xyz456
# Use .env file (add to .gitignore)
AIVA_API_KEY=aiva_live_abc123xyz456
# Access in code
const apiKey = process.env.AIVA_API_KEY;
`"
### Key Rotation
Rotate API keys every 90 days for security:
- Generate new API key
- Update production environment variables
- Deploy with new key
- Verify functionality
- Revoke old key after 24 hours
### Rate Limit Monitoring
Track your API usage in the dashboard:
**Settings → API Access → Usage Analytics**
View:
- Requests per minute (current)
- Requests today
- Rate limit remaining
- Most called endpoints
- Error rate
**Rate Limit Alerts:**
- Email notification at 80% usage
- Dashboard warning at 90% usage
- Requests rejected at 100% usage -
Building something with the AIVA API or MCP server? We read every developer message.
Talk to us