Scaleway API Keys API

An API key is a unique identifier, used to authenticate requests made to the Scaleway API. An API key consists of an access key and a secret key. The access key is like a unique ID or username, and not a sensitive piece of information. The secret key however is more sensitive, as it is like a password to authenticate the access key. Previously, an API key was associated with a single Scaleway [Project](https://www.scaleway.com/en/docs/iam/concepts/#api-key#project). The API key therefore had full read/write access to all resources on this Project, and only this Project. With IAM, an API key is now associated with an IAM [user](https://www.scaleway.com/en/docs/iam/concepts/#api-key#user) or [application](https://www.scaleway.com/en/docs/iam/concepts/#api-key#application). This allows fine-grained access to be defined for the IAM user bearing the API key across different Organizations, Projects, and resources.

Business capability
Identity & Access Management BC-620.20

Operations 5

GET /iam/v1alpha1/api-keys List API keys #
POST /iam/v1alpha1/api-keys Create an API key #
GET /iam/v1alpha1/api-keys/{access_key} Get an API key #
PATCH /iam/v1alpha1/api-keys/{access_key} Update an API key #
DELETE /iam/v1alpha1/api-keys/{access_key} Delete an API key #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/scaleway-api-keys-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

scaleway-api-keys-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: IAM API Keys API
  description: Identity and Access Management (IAM) allows you to share access to the management of your Scaleway resources and Organization settings, in a controlled and secure manner.
  version: v1alpha1
servers:
- url: https://api.scaleway.com
tags:
- name: API Keys
  description: An API key is a unique identifier, used to authenticate requests made to the Scaleway API.
paths:
  /iam/v1alpha1/api-keys:
    get:
      tags:
      - API Keys
      operationId: ListAPIKeys
      summary: List API keys
      description: List API keys. By default, the API keys listed are ordered by creation date in ascending order. This can be modified via the `order_by` field. You can define additional parameters for your query such as `editable`, `expired`, `access_key` and `bearer_id`.
      parameters:
      - in: query
        name: order_by
        description: Criteria for sorting results.
        schema:
          type: string
          enum:
          - created_at_asc
          - created_at_desc
          - updated_at_asc
          - updated_at_desc
          - expires_at_asc
          - expires_at_desc
          - access_key_asc
          - access_key_desc
          x-enum-descriptions:
            values:
              created_at_asc: Creation date ascending
              created_at_desc: Creation date descending
              updated_at_asc: Update date ascending
              updated_at_desc: Update date descending
              expires_at_asc: Expiration date ascending
              expires_at_desc: Expiration date descending
              access_key_asc: Access key ascending
              access_key_desc: Access key descending
          default: created_at_asc
      - in: query
        name: page
        description: Page number. Value must be greater or equal to 1.
        schema:
          type: integer
          format: int32
      - in: query
        name: page_size
        description: Number of results per page. Value must be between 1 and 100.
        schema:
          type: integer
          format: uint32
      - in: query
        name: organization_id
        description: ID of Organization.
        schema:
          type: string
      - in: query
        name: editable
        description: Defines whether to filter out editable API keys or not.
        schema:
          type: boolean
      - in: query
        name: expired
        description: Defines whether to filter out expired API keys or not.
        schema:
          type: boolean
      - in: query
        name: access_key
        description: Filter by access key (deprecated in favor of `access_keys`).
        schema:
          type: string
          deprecated: true
      - in: query
        name: description
        description: Filter by description.
        schema:
          type: string
      - in: query
        name: bearer_id
        description: Filter by bearer ID.
        schema:
          type: string
      - in: query
        name: bearer_type
        description: Filter by type of bearer.
        schema:
          type: string
          enum:
          - unknown_bearer_type
          - user
          - application
          x-enum-descriptions:
            values:
              unknown_bearer_type: Unknown bearer type
              user: User
              application: Application
          default: unknown_bearer_type
      - in: query
        name: access_keys
        description: Filter by a list of access keys.
        schema:
          type: array
          items:
            type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/scaleway.iam.v1alpha1.ListAPIKeysResponse'
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X GET \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  \"https://api.scaleway.com/iam/v1alpha1/api-keys?organization_id=string\""
      - lang: HTTPie
        source: "http GET \"https://api.scaleway.com/iam/v1alpha1/api-keys\" \\\n  X-Auth-Token:$SCW_SECRET_KEY \\\n  organization_id==string"
    post:
      tags:
      - API Keys
      operationId: CreateAPIKey
      summary: Create an API key
      description: Create an API key. You must specify the `application_id` or the `user_id` and the description. You can also specify the `default_project_id`, which is the Project ID of your preferred Project, to use with Object Storage. The `access_key` and `secret_key` values are returned in the response. Note that the secret key is only shown once. Make sure that you copy and store both keys somewhere safe.
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/scaleway.iam.v1alpha1.APIKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                application_id:
                  type: string
                  description: ID of the application.
                  nullable: true
                  x-one-of: bearer
                user_id:
                  type: string
                  description: ID of the user.
                  nullable: true
                  x-one-of: bearer
                expires_at:
                  type: string
                  description: Expiration date of the API key. (RFC 3339 format)
                  format: date-time
                  example: '2022-03-22T12:34:56.123456Z'
                  nullable: true
                default_project_id:
                  type: string
                  description: Default Project ID to use with Object Storage.
                  nullable: true
                description:
                  type: string
                  description: Description of the API key (max length is 200 characters).
              x-properties-order:
              - application_id
              - user_id
              - expires_at
              - default_project_id
              - description
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X POST \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"description\":\"string\"}' \\\n  \"https://api.scaleway.com/iam/v1alpha1/api-keys\""
      - lang: HTTPie
        source: "http POST \"https://api.scaleway.com/iam/v1alpha1/api-keys\" \\\n  X-Auth-Token:$SCW_SECRET_KEY \\\n  description=\"string\""
  /iam/v1alpha1/api-keys/{access_key}:
    get:
      tags:
      - API Keys
      operationId: GetAPIKey
      summary: Get an API key
      description: Retrieve information about an API key, specified by the `access_key` parameter. The API key's details, including either the `user_id` or `application_id` of its bearer are returned in the response. Note that the string value for the `secret_key` is nullable, and therefore is not displayed in the response. The `secret_key` value is only displayed upon API key creation.
      parameters:
      - in: path
        name: access_key
        description: Access key to search for.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/scaleway.iam.v1alpha1.APIKey'
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X GET \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  \"https://api.scaleway.com/iam/v1alpha1/api-keys/{access_key}\""
      - lang: HTTPie
        source: "http GET \"https://api.scaleway.com/iam/v1alpha1/api-keys/{access_key}\" \\\n  X-Auth-Token:$SCW_SECRET_KEY"
    patch:
      tags:
      - API Keys
      operationId: UpdateAPIKey
      summary: Update an API key
      description: Update the parameters of an API key, including `default_project_id` and `description`.
      parameters:
      - in: path
        name: access_key
        description: Access key to update.
        required: true
        schema:
          type: string
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/scaleway.iam.v1alpha1.APIKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                default_project_id:
                  type: string
                  description: New default Project ID to set.
                  nullable: true
                description:
                  type: string
                  description: New description to update.
                  nullable: true
                expires_at:
                  type: string
                  description: New expiration date of the API key. (RFC 3339 format)
                  format: date-time
                  example: '2022-03-22T12:34:56.123456Z'
                  nullable: true
              x-properties-order:
              - default_project_id
              - description
              - expires_at
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X PATCH \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{}' \\\n  \"https://api.scaleway.com/iam/v1alpha1/api-keys/{access_key}\""
      - lang: HTTPie
        source: "http PATCH \"https://api.scaleway.com/iam/v1alpha1/api-keys/{access_key}\" \\\n  X-Auth-Token:$SCW_SECRET_KEY"
    delete:
      tags:
      - API Keys
      operationId: DeleteAPIKey
      summary: Delete an API key
      description: Delete an API key. Note that this action is irreversible and cannot be undone. Make sure you update any configurations using the API keys you delete.
      parameters:
      - in: path
        name: access_key
        description: Access key to delete.
        required: true
        schema:
          type: string
      responses:
        '204':
          description: ''
      security:
      - scaleway: []
      x-codeSamples:
      - lang: cURL
        source: "curl -X DELETE \\\n  -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n  \"https://api.scaleway.com/iam/v1alpha1/api-keys/{access_key}\""
      - lang: HTTPie
        source: "http DELETE \"https://api.scaleway.com/iam/v1alpha1/api-keys/{access_key}\" \\\n  X-Auth-Token:$SCW_SECRET_KEY"
components:
  schemas:
    scaleway.iam.v1alpha1.ListAPIKeysResponse:
      type: object
      properties:
        api_keys:
          type: array
          description: List of API keys.
          items:
            $ref: '#/components/schemas/scaleway.iam.v1alpha1.APIKey'
        total_count:
          type: integer
          description: Total count of API Keys.
          format: uint32
      x-properties-order:
      - api_keys
      - total_count
    scaleway.iam.v1alpha1.APIKey:
      type: object
      properties:
        access_key:
          type: string
          description: Access key of the API key.
        secret_key:
          type: string
          description: Secret key of the API Key.
          nullable: true
        application_id:
          type: string
          description: ID of application that bears the API key.
          nullable: true
          x-one-of: bearer
        user_id:
          type: string
          description: ID of user that bears the API key.
          nullable: true
          x-one-of: bearer
        description:
          type: string
          description: Description of API key.
        created_at:
          type: string
          description: Date and time of API key creation. (RFC 3339 format)
          format: date-time
          example: '2022-03-22T12:34:56.123456Z'
          nullable: true
        updated_at:
          type: string
          description: Date and time of last API key update. (RFC 3339 format)
          format: date-time
          example: '2022-03-22T12:34:56.123456Z'
          nullable: true
        expires_at:
          type: string
          description: Date and time of API key expiration. (RFC 3339 format)
          format: date-time
          example: '2022-03-22T12:34:56.123456Z'
          nullable: true
        default_project_id:
          type: string
          description: Default Project ID specified for this API key.
        editable:
          type: boolean
          description: Defines whether or not the API key is editable.
        deletable:
          type: boolean
          description: Defines whether or not the API key is deletable.
        managed:
          type: boolean
          description: Defines whether or not the API key is managed.
        creation_ip:
          type: string
          description: IP address of the device that created the API key.
      x-properties-order:
      - access_key
      - secret_key
      - application_id
      - user_id
      - description
      - created_at
      - updated_at
      - expires_at
      - default_project_id
      - editable
      - deletable
      - managed
      - creation_ip
  securitySchemes:
    scaleway:
      in: header
      name: X-Auth-Token
      type: apiKey