API credential inventory

Available since 1.0.25. Track what an application uses, who owns it, when action is due and how an operator can replace it.

Dokumentacija je trenutno dostupna na engleskom. Sučelje proizvoda i ugrađena pomoć dostupni su na hrvatskom.

Store metadata and vault references only. Never enter token values, passwords or client-secret values into names, URLs, runbooks or other text fields: metadata is retained in history and exports. This module does not automatically discover, validate, issue, rotate, distribute or revoke credentials at a provider. It does not create authentication tokens for the ens0key API.

1. Record ownership and context

Open API Credentials and add a record manually, through the REST API or with CSV import. Supported categories include API tokens, personal access tokens (PATs), API keys and OAuth client secrets.

  • ▸Context: application, environment, provider, criticality and consumers.
  • ▸Identity: the principal authenticated by the credential, the issuer account and issuing actor.
  • ▸Ownership: responsible owner, team and notification email. The owner is an operational contact, not necessarily an ens0key user.
  • ▸Replacement: issuer/replacement portal URLs, a vault reference and an operator runbook. Use URLs without embedded credentials or query parameters.

2. Set expiry and review deadlines

Select a known expiry date, no fixed expiry (after confirming that at the issuer), or unknown expiry. Rotation and review deadlines are separate operator policies; they do not change the actual provider expiry. Date entry uses UTC; details display dates in the browser's time zone.

Default expiry alerts are 30, 14, 7 and 1 days before expiry. The default stale-review interval is 90 days. Findings also cover expired records, overdue rotation or review, unknown expiry and missing ownership.

3. Act on findings

  • ▸Acknowledge records that you have seen a finding; it does not fix the condition or move a deadline.
  • ▸Review records who checked the metadata and when. Verify the issuer, owner, consumers and runbook first; this is not a token-validity check.
  • ▸Replace or revoke at the issuer, update consumers through your operational process, then update the inventory to reflect the completed action.
  • ▸Archive retires the record while retaining metadata and history. Retired and revoked records stop generating active lifecycle warnings.

Configure notifications to the owner or a fallback recipient. Acknowledging one expiry stage does not suppress a later, more urgent stage. Findings resolve when the underlying condition clears.

4. Use the operator workspace

Priority shortcuts and sorting bring records needing attention to the top. Filters, pagination and mobile cards support daily work. The detail view separates overview, replacement procedure, alerts and change history. CSV export includes all matching records, regardless of the current display page.

CSV import creates new records; it does not reconcile provider identities or update existing entries. Review imports before repeating them to avoid duplicates. A saved record, future expiry date or review confirmation is not proof that the credential works at the provider.