Scoped API Keys

If you manage DNS zones for several customers through our DNS API, you previously only had a single API key per account, valid for every zone at once. That became awkward as soon as a key needed to be handed to one specific customer, for example for automatic Let’s Encrypt certificate renewal via DNS-01. From now on you can keep these cleanly separated.

In the client area under Account > Update Account Details, next to the existing API key, you will now find the Manage API Keys button. Use it to create as many additional keys as you like, each limited to the domains you select.

Scoped access icon

Scoped accessEach additional key only reaches the domains you explicitly selected when creating it, never the rest of your account.
Self-service icon

Fully self-serviceNo need to contact us, you create and manage the keys directly in the client area.
Instant revocation icon

Revoke instantlyNo longer need a key, or no longer trust it? Revoke it with one click, without affecting your other keys.
Automatic protection icon

Protected automaticallyIf a domain changes ownership, any key scoped to it loses access instantly, with no manual cleanup required.
Automation-ready icon

Automation readyIdeal for win-acme, acme.sh, or your own scripts that should only ever touch a single domain.
Selectable permission level icon

Choose the permission levelDecide per key whether it may only trigger automatic certificate renewal via DNS-01, or also allow full DNS management of the domain.

Setting up a scoped key

Open your account details in the client area and click Manage API Keys next to the API key field. Give it a label, select one or more domains, and decide whether the key should only be used for automatic certificate renewal or should also allow full DNS management of those domains. The generated key is shown once, note it down right away.

 

Interface for creating a scoped API keyNew client area interface: select domains and create a restricted key on the spot

 

Who benefits most

This is especially useful for service providers managing domains on behalf of their own customers: instead of handing out the full account key, each customer gets a key limited to their own domain. It also helps limit the blast radius of automated DNS-01 certificate renewal (for example with win-acme or acme.sh) to exactly the domain it needs.

You can find more on the DNS API itself in our DNS API knowledge base article.

Related Post
Dateitransfer.ch: Secure File Sharing with up to 50 GB

Dateitransfer.ch von FireStorm ermöglicht sicheren Datenaustausch mit bis zu 50 GB pro Transfer – auf Schweizer Servern, verschlüsselt und ohne Registrierung.

Read more
Imunify 360 at FireStorm – Maximum web server protection for FireStorm customers

At FireStorm, we have updated the security software for our customers. Therefore your websites and emails are now even more secure. The reason for this is a comprehensive security platform for web servers. We are talking about Imunify 360, a Plesk extension, which immediately offers our customers more protection. In this short article you will […]

Read more