Skip to main content

API Keys

Create API keys in the platform admin dashboard. The platform uses one shared API key. Clients / brokers are separated by their unique identifier, not by different keys. Pass both as query parameters when embedding the Organization Users panel at https://manage.iccandle.site/.

Treat API keys as secrets

API keys grant access to organization data across clients under that platform. Never commit them to source control, paste them into public tickets, or ship them in client-side code outside the controlled embed URL. Rotate a key immediately if it is leaked.

Open API Keys​

  1. Sign in to the platform admin dashboard — see Admin.
  2. Open API Keys from the sidebar.

Create an API key​

  1. Select Create API key.
  2. Choose the service type required for the platform (for Organization Users embed access, use the authentication / org key type).
  3. Optionally leave Create as active checked so the key works immediately.
  4. Select Create.
  5. Copy the key and store it securely.
  6. Give each client:
    • the same platform API key (apikey)
    • that client's unique identifier

They load the embed like this:

https://manage.iccandle.site/?apikey=YOUR_API_KEY&identifier=YOUR_IDENTIFIER

Full embed options (theme, lang, primary): Clients / Brokers.

Manage existing keys​

From the API key list you can:

ActionResult
CopyCopy the key value
Update statusSet New, Active, or Revoked
FilterSearch by email or key fragment

Revoked keys stop working immediately — including any live Organization Users embeds that still use that key.

How the embed uses the key​

Inside https://manage.iccandle.site/:

  1. The host passes apikey and identifier in the URL.
  2. The panel configures its HTTP client with those values (x-api-key header + identifier query param).
  3. Backend calls for users, credit bundle, and plan assignment use that key.
  4. The full key is not rendered as UI content in the panel — but it remains visible in the page URL.

If the key or identifier is wrong, the users list shows Authentication failed or Could not load this account. Ask the client to refresh after you issue a corrected key.

Security recommendations​

  • One API key per platform (optionally separate keys for production vs staging). Separate clients with unique identifier values, not separate keys.
  • Prefer serving the iframe from an authenticated staff page so the URL is not publicly guessable.
  • Revoke compromised keys, then update every client's embed URL that used that key.
  • Do not log full embed URLs that contain live keys.