Skip to main content
Every API request is made with an API key. A key belongs to your account and acts as you, limited to the permissions you give it. You can have as many keys as you like — one per script or integration is a good habit, so you can revoke one without breaking the others.

Create a key

1

Open API & Integrations

Sign in to dashboard.storiza.store and open API & Integrations from the sidebar.
2

Choose Create key and fill in the details

3

Copy the key

The key is shown once, right after you create it. It starts with stz_. Storiza stores only a fingerprint of it, so if you lose it, create a new one and revoke the old.

Use a key

Send it in the Authorization header as a bearer token:
There is no separate login step and no token to refresh — the key itself is the credential, on every request.

Permissions

A permission is <area>:<action>. Read lets a key look; Manage (:write) lets it change things too. Every endpoint in the API reference states the one it needs. The dashboard offers a few more permissions — for support tickets and the reseller program, for example. Those areas are used from the dashboard and are not part of the public API, so a key does not need them.
Grant the least that works. A monitoring script needs vps:read, not vps:write. A key that can only read cannot delete a server, however it is misused.
Some things are deliberately not possible with a key, whatever its permissions: creating or changing API keys, changing your password, email or two-factor settings, and deleting your account. Those happen in the dashboard only, so a leaked key can never be used to lock you out or to create more keys.

Restrict by IP address

If you know where a key will be used from — a server, a CI runner — list those addresses under Allowed IP addresses. Requests from anywhere else are refused even with the correct key. Single addresses and ranges both work, for IPv4 and IPv6 (for example 203.0.113.7 or 203.0.113.0/24).

When a request is refused

See Responses and errors for the full error format.

Rotate and revoke

Revoke a key from API & Integrations with Revoke. Anything using it stops working immediately, and it cannot be undone. To rotate a key without downtime: create the new key, deploy it, confirm it is being used (the list shows each key’s Last used time), then revoke the old one.
Treat a key like a password. Never commit it to a repository, paste it into a support ticket, or ship it in code that runs in a browser or a mobile app — anyone who can read it can act as you within its permissions.