Create a key
1
Open API & Integrations
Sign in to dashboard.storiza.store and open API & Integrations from the sidebar.
2
Choose Create key and fill in the details
3
Copy the key
The key is shown once, right after you create it. It starts with
stz_. Storiza stores only a fingerprint of it, so if you lose it, create a new one and revoke the old.Use a key
Send it in theAuthorization header as a bearer token:
Permissions
A permission is<area>:<action>. Read lets a key look; Manage (:write) lets it change things too. Every endpoint in the API reference states the one it needs.
The dashboard offers a few more permissions — for support tickets and the reseller program, for example. Those areas are used from the dashboard and are not part of the public API, so a key does not need them.
Some things are deliberately not possible with a key, whatever its permissions: creating or changing API keys, changing your password, email or two-factor settings, and deleting your account. Those happen in the dashboard only, so a leaked key can never be used to lock you out or to create more keys.
Restrict by IP address
If you know where a key will be used from — a server, a CI runner — list those addresses under Allowed IP addresses. Requests from anywhere else are refused even with the correct key. Single addresses and ranges both work, for IPv4 and IPv6 (for example203.0.113.7 or 203.0.113.0/24).
When a request is refused
See Responses and errors for the full error format.