What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
Administrators
This guide covers managing API keys in Agility CMS, including key types, security, and best practices.
This guide covers managing API keys in Agility CMS, including key types, security, and best practices.
Agility CMS provides three types of API keys:
Purpose: Access published content in production
Use Case:
Security:
Purpose: Access draft content for preview
Use Case:
Security:
Purpose: Validate preview keys
Use Case:
Security:
The Security Key is not used for webhooks. Agility never sends it with a webhook. To verify that a webhook request came from Agility, tick Enable secure delivery on the webhook in Settings → Webhooks. Each webhook then gets its own
whsec_signing secret. See Verifying Signed Webhooks.
API keys have different permissions:
Environment Variables:
AGILITY_API_FETCH_KEY=your-fetch-key
AGILITY_API_PREVIEW_KEY=your-preview-key
AGILITY_SECURITY_KEY=your-security-key
Never:
// Production content access
const sdk = agility.getApi({
guid: process.env.AGILITY_GUID,
apiKey: process.env.AGILITY_API_FETCH_KEY,
isPreview: false
})
// Draft content access
const sdk = agility.getApi({
guid: process.env.AGILITY_GUID,
apiKey: process.env.AGILITY_API_PREVIEW_KEY,
isPreview: true
})
Your site's preview route uses the Security Key to validate the preview key it receives before it turns on preview mode. Keep it in a server-side environment variable such as AGILITY_SECURITY_KEY.
To secure a webhook endpoint, use that webhook's whsec_ signing secret instead. Verifying Signed Webhooks has the verification code.
Issue: API calls return 401 Unauthorized
Solutions:
Issue: Need to regenerate compromised key
Steps:
Next: Webhooks - Webhook configuration