API Keys
Create API keys in the platform admin dashboard. The platform uses one shared API key. Clients / brokers are separated by their unique identifier, not by different keys. Pass both as query parameters when embedding the Organization Users panel at https://manage.iccandle.site/.
API keys grant access to organization data across clients under that platform. Never commit them to source control, paste them into public tickets, or ship them in client-side code outside the controlled embed URL. Rotate a key immediately if it is leaked.
Open API Keys
- Sign in to the platform admin dashboard — see Admin.
- Open API Keys from the sidebar.
Create an API key
- Select Create API key.
- Choose the service type required for the platform (for Organization Users embed access, use the authentication / org key type).
- Optionally leave Create as active checked so the key works immediately.
- Select Create.
- Copy the key and store it securely.
- Give each client:
- the same platform API key (
apikey) - that client's unique identifier
- the same platform API key (
They load the embed like this:
https://manage.iccandle.site/?apikey=YOUR_API_KEY&identifier=YOUR_IDENTIFIER
Full embed options (theme, lang, primary): Clients / Brokers.
Manage existing keys
From the API key list you can:
| Action | Result |
|---|---|
| Copy | Copy the key value |
| Update status | Set New, Active, or Revoked |
| Filter | Search by email or key fragment |
Revoked keys stop working immediately — including any live Organization Users embeds that still use that key.
How the embed uses the key
Inside https://manage.iccandle.site/:
- The host passes
apikeyandidentifierin the URL. - The panel configures its HTTP client with those values (
x-api-keyheader +identifierquery param). - Backend calls for users, credit bundle, and plan assignment use that key.
- The full key is not rendered as UI content in the panel — but it remains visible in the page URL.
If the key or identifier is wrong, the users list shows Authentication failed or Could not load this account. Ask the client to refresh after you issue a corrected key.
Security recommendations
- One API key per platform (optionally separate keys for production vs staging). Separate clients with unique
identifiervalues, not separate keys. - Prefer serving the iframe from an authenticated staff page so the URL is not publicly guessable.
- Revoke compromised keys, then update every client's embed URL that used that key.
- Do not log full embed URLs that contain live keys.
Related guides
- Clients / Brokers
- Seamless auth (sub-org) — authenticate end users under a broker
identifier - Seamless user authentication — corporate partner flow without
identifier