The API Keys page allows administrators to create and manage credentials used by Report Designer and applications that access the WebReports Management API.
Important: API-key secrets provide access to WebReports. Treat them like passwords and share them only with authorized users or applications.
Open the API Keys page
- Sign in to WebReports with an administrator account.
- Select Configuration.
- Select API Keys.
The page lists existing API keys and provides options to search, filter, sort, add, edit, and delete them.
API Keys management page in WebReports.
Find an existing API key
Use the available controls to locate a key:
- Enter text in the search field to find matching records.
- Use the filter options to narrow the displayed results.
- Select a column heading to change the sort order.
- Use the pagination controls to move between result pages.
Select an API key before using Edit or Delete.
Add an API key
- Select Add.
- Enter an Application Name that identifies the application or integration.
- Select a Key Type:
- Report Designer
- Management API
- Complete the fields required for the selected key type.
- Review the generated secret and all access restrictions.
- Select Add API Key to create the key.
Select Cancel to close the form without creating the key.
Available API-key types in WebReports.
Create a Report Designer API key
Select Report Designer when the key will be used to connect Report Designer to WebReports.
Complete the following fields:
- Application Name — Enter a recognizable name for the Report Designer installation or integration.
- Key Type — Select Report Designer.
- Publisher User — Select the WebReports user whose publishing access will be associated with the key.
- Description — Enter information that explains the key’s purpose or identifies its owner.
- Allowed Host Names or IP Addresses — Enter the hosts permitted to use the key. Separate multiple entries with semicolons.
- Secret — Use the generated credential when configuring the authorized application.
After reviewing the settings, select Add API Key.
Settings used to create a Report Designer API key.
Important: Select the Publisher user carefully. The key may allow Report Designer to perform actions associated with that user’s access.
Create a Management API key
Select Management API when an authorized application or integration requires access to supported WebReports management functions.
Complete the following fields:
- Application Name — Enter a recognizable name for the application or integration.
- Key Type — Select Management API.
- Description — Explain the key’s purpose or identify its owner.
- Allowed Host Names or IP Addresses — Enter the hosts permitted to use the key. Separate multiple entries with semicolons.
- Secret — Use the generated credential when configuring the authorized application.
Report permissions
Select only the report permissions the application requires:
- Queue Reports — Allows the application to submit reports for processing.
- Publish Reports — Allows the application to publish reports.
- Manage Reports and Assignments — Allows the application to manage reports and their assignments.
- View Completed Reports — Allows the application to access completed reports.
Administration permissions
Select only the administrative permissions the application requires:
- Manage UDFs — Allows the application to manage user-defined fields.
- Manage Users and Roles — Allows the application to manage WebReports users and roles.
- View Logs — Allows the application to view supported WebReports logs.
- View Connections — Allows the application to view connection information.
After reviewing the fields and permissions, select Add API Key.
Settings and permissions available for a Management API key.
Important: Follow the principle of least privilege. Enable only the permissions required by the application.
Restrict allowed hosts
Use Allowed Host Names or IP Addresses to limit where an API key can be used.
When entering multiple values, separate them with semicolons. Verify each hostname or IP address before creating or updating the key.
Restricting a key to known hosts helps reduce unauthorized use if its secret is exposed.
Protect the API-key secret
Follow these practices when handling a secret:
- Store it in an approved credential manager or secure application configuration.
- Do not send it through email, chat, tickets, or other unsecured channels.
- Do not include it in documentation or screenshots.
- Do not commit it to source control.
- Provide it only to authorized users or applications.
- Replace a key if its secret may have been exposed.
Important: Any secret displayed while preparing this article must not be used. Close the form without creating the key, or delete the key and create a replacement if it was saved.
Edit an API key
- Locate and select the API key.
- Select Edit.
- Update the available settings, restrictions, or permissions.
- Review the changes.
- Save the API key.
Review integrations that use the key after making changes. Updated host restrictions, users, or permissions may prevent an existing integration from working.
Delete an API key
- Locate and select the API key.
- Select Delete.
- Review the selected key carefully.
- Confirm the deletion when prompted.
Important: Deleting a key prevents applications using that credential from accessing WebReports. Verify that the key is no longer needed before deleting it.
Comments
0 comments
Please sign in to leave a comment.