---
title: "API keys — React Box documentation"
description: "Create an organization API key, pick its scopes, use it in the x-api-key header, disable or revoke it."
url: https://www.react-box.com/en/docs/developers/api-keys
lang: en
---

DevelopersAPI keys

# API keys

An organization key authenticates an integration, with chosen scopes and an expiry.

Updated on October 2, 2026

## Create a key

Reserved to organization admins: a key is an identity, not a setting.

1. Open Settings → API keys  
The screen lists existing keys, their status, their scopes and their last call.
2. Name the key  
One name per use — “accounting sync”, “collection bot” — so you know what to revoke the day it matters.
3. Pick scopes and expiry  
Tick only what the integration needs. The default expiry is a year; a key with no expiry is possible, and easy to forget.
4. Copy the secret  
It is shown once, right after creation. It is stored nowhere: if it is lost, replace it with a new key.

## Scopes

What the key is allowed to do, and nothing more.

* Scopes are the product's permissions — the same ones a custom role grants.
* A missing scope cannot be worked around: the call is refused with a 403, even where the endpoint exists.
* Capabilities an organization cannot hold are stripped on every call, not only at creation.
* A scope that depends on a module you do not hold stays closed until the module is active.
* A key carries scopes but no role, so a vault folder restricted to specific roles stays invisible to it: its documents are silently absent from the lists, without an error. Keep the folders an integration must read open to every role.
* Capabilities that follow the administrator role never travel through a key: the Atlas assistant refuses every key, whatever its scopes. The MCP server does accept one — a key is created by an administrator, which is the same lock.

## Using the key

Send the secret in the x-api-key header. No other header is required.

```
curl https://www.react-box.com/api/v1/invoices \
  -H "x-api-key: rbx_…"
```

## Limits

Keys are included in the subscription; these limits protect the platform, not your bill.

* 20 usable keys per organization. A revoked or expired key does not count.
* Expiry from 1 to 730 days, or none at all.
* 120 requests per minute per key. Beyond that the API answers 429 with a retry-after header.
* Lists return 50 items per page, 100 at most over REST. The MCP tools go up to 200.
* Every write leaves a trace: a draft created with a key shows up in the record's history, naming the key that created it.

## Lifecycle

Four events stop a key.

* Disabling suspends the key without deleting it: the integration stops, the history stays readable.
* Revoking deletes the key for good, effective on the next call.
* Keys created by someone are disabled when they lose access to the organization.
* A suspended or deleted organization closes its keys along with its sessions.

Treat the secret like a password

It stands for the whole organization, within its scopes. Keep it in a secret manager, never in a code repository, and revoke it at the first sign of exposure.
