An API key lets a developer, or a tool you run, use the Mateflow Open API to read and write your community's data. You create and revoke API keys under Admin → Settings → Integrations → API Access. Each key works for one community only.
Who can do this: Owners and admins. · Where: Web (admin console). · Plan: API access, and how many API requests a day your community can make, depend on your platform plan.
API keys are per community
API keys belong to a single community, and requests made with a key always act on that community. To connect several communities, create a key in each one's admin console.
The creator dashboard (app.mateflow.com) doesn't have API keys. Workspace-level keys there have been replaced by per-community keys. A community's Overview page in the dashboard links to its Integrations page.
Create an API key
- Go to Admin → Settings → Integrations and open the API Access tab.
- Click Generate New Key.
- Enter a Key Name that says what it's for, such as the tool that will use it.
- Under Scopes & Permissions, tick only the permissions the integration needs. See the next section.
- Optional: under IP Whitelist (Optional), enter the IP addresses or ranges allowed to use the key, separated by commas.
- Click Generate New Key.
- Copy the key from API Key Generated, store it somewhere safe, then click Done.
You can see the full key only once. If you lose it, generate a new key and revoke the old one.
If the API Access tab shows an upgrade prompt, your platform plan doesn't include API access. The API Endpoint card shows the base URL for requests and your plan's daily request limit, which resets at 00:00 UTC.
API key scopes (permissions)
| Scope | What it allows |
|---|---|
| Read community | Read community profile, settings, and metadata |
| Read content | Read posts, feeds, replies, and search results |
| Write content | Create, edit, and delete posts and replies |
| Upload media | Request upload tokens; also covers reading signed media URLs |
| Read media | Read signed URLs for existing media |
| Read spaces | List spaces and read space details |
| Read members | Look up members and read basic profiles, including their access groups |
| Invite members | Invite people by email or by an invitation link |
Read members and Invite members are listed under Sensitive access. Read members lets the integration check whether an email address belongs to your community. With Invite members, invitations are sent as the community owner unless the integration names another inviter, and invited people always join as members. API invitations can include access groups. See How access groups work.
A key's scopes can't be changed later. Older keys may show All (legacy): they keep only the scopes that existed when they were created. Create a new key to use newer scopes.
Revoke an API key
- On the API Access tab, find the key under API Keys.
- Open its actions menu and click Revoke Key.
- Confirm. Revoking can't be undone, and any tool using the key stops working.
The list shows each key's Status (Active, Expired, or Revoked) and Last Used date. API requests don't appear in Delivery Logs, so Last Used is how you check whether a key is still in use. Disconnecting Slack, Discord, or Zapier doesn't revoke any API keys.
Keep API keys secure
- Keep API keys on a server, not in a website or app that others can download, and send requests over HTTPS.
- Give each tool its own key with only the scopes it needs, so you can revoke one without breaking the others.
- Add an IP Whitelist when the tool calls from fixed addresses.
- Revoke a key right away if it may have leaked, then create a replacement.
Where to find the API documentation
The API reference covers endpoints, request and response formats, scopes, error codes, and code samples. On the API Access tab, the Developer documentation card has an Open documentation button that goes to mateflow.com/developers. Send that link to your developer. They don't need an account in your community, and the page is available even if your plan doesn't include API access.
Related articles
Was this guide helpful?