Skip to main content
API keys allow your WordPress sites to connect securely to your organization and retrieve update information for your private plugins and themes.

Overview

API keys are managed from Settings → API Keys in the dashboard. Use Generate new API key to create one, and the edit button of a key to change its description or permissions. When an organization is created, two API Keys are generated named publisher_key and readonly. Both of the keys are scoped on “themes” and “plugins”. The readonly key let you see the list and download your different plugins and themes versions but cannot be used to upload a new artifact.
The publisher_key should be kept securely. Anyone with this key can publish new versions and edit the metadata of your plugins and themes (create, read, update). It cannot delete items or access billing, users or organization settings — but it should still never be exposed publicly.
You can revoke a key anytime by deleting it. Be careful, each key are unique so if you delete it, you will have to change the key everywhere you use it.

Understanding scopes and permissions

API Keys can be scoped on plugins and themes. For each scope, you can choose to apply permissions gradually:
  1. read : See list and plugin or theme details
  2. update : Upload a new artifact and update plugin or theme details
  3. create : Create a new plugin or theme
  4. delete : Delete an existing plugin or theme
Managing API Keys requires the api_keys scope: owners and admins have it by default, and it can also be granted to a member with a custom role.
Need more details about scopes and permissions? Check out the full list of available scopes and what each permission allows on this page.