In this article
An API key creates an integration between DNSFilter and other products or applications. Each key is a JSON Web Token (JWT), also called a key or token, and shares data via the JWT. DNSFilter users have self-service access to API keys through the DNSFilter dashboard. For more details, see the developer API documentation.
Rate limiting was introduced on API requests on February 4, 2025. For current limits, see API Rate Limits.
How API keys work
An API key is associated with the user who created it and takes on that user's permissions. Each user is limited to five API keys. The following rules apply to all API keys.
| Rule | Detail |
|---|---|
| API keys are associated with the user, not an Organization | A user's API keys appear only in their own account, even when the user belongs to multiple Organizations. |
| The API key takes on the same permissions as the user | The key is associated with the user and provides the same level of access granted to that user in the system. This applies to MSP Organization users and client users. |
| Only a user can revoke or delete their own keys | Organization owners and admins cannot revoke or delete a user's key. |
| Limit of five API keys per user | Only keys in active status count toward this total. Users receive an error message from the dashboard when they try to create more than five keys. Users can revoke or delete unused keys to add new keys. |
| There is no expiration warning or reminder | The API key dashboard displays the expiration date. Use automation practices to prevent any lapse in API integration. If a key expires, the integration returns an error code stating the user is not authorized until the API key is updated. |
Caution: Account owners should not create API keys. DNSFilter encourages principle of least privilege practices when using API keys: if an API key becomes compromised, this minimum layer of protection can prevent serious damage to the account.
Generate a DNSFilter API Key
To generate an API key:
- Log in to the DNSFilter dashboard and navigate to your account icon.
- Select Account Settings.
- Select the Security tab.
- Scroll to API Keys.
- Select + Create Key.
-
Enter a key Name.
This name is not editable after the key is created.
- Select an Expiration from the dropdown.
- Select Generate Key.
-
Copy the API key.
Save does not function until the key is copied.
Caution: This is the only time the key is available. Store the key in a password vault if it may need to be copied again in the future.
- Select Save to return to the API key dashboard.
The API key is now visible in the dashboard. Use the API key in an application or service by following its standard configuration process.
API Key dashboard fields
A key dashboard populates in the account after at least one key is created. The following fields are available in the dashboard.
| Field | Description |
|---|---|
| Status | The API key status is either active, revoked, or expired. Deleted keys are removed from the dashboard. |
| API Key | This column displays the key name and redacted token ID. |
| Key Dates | This column displays the expiration date and time, and the creation date and time. |
| Actions | Select the more icon to revoke or delete a key. |
Revoke or delete a DNSFilter API key
Revoke or delete a token when it is no longer needed. To ensure uninterrupted configurations, replace API keys before completing these steps.
To revoke or delete an API key:
- Navigate to the API key dashboard in the account.
- From the Actions menu, select Revoke or Delete for the unneeded key.
- Confirm the action in the prompt.
The token is no longer available for use after the action is confirmed. A revoked key's Status updates to revoked, and deleted keys disappear from the dashboard. Any current applications using the key return an error message and require a new token to configure with DNSFilter.
Automate API key renewal
Automating key rotation requires one manual step to start: generate the first key through the dashboard and store it securely. From that point, use the active key to automate all future renewals through the API.
To automate API key renewal:
- Create a replacement key using the current active key, before the current key's expiration date.
- Update the connected integration or secret store with the replacement key.
- Validate the replacement key.
- Revoke the original key.
The integration now uses the replacement key. Repeat this process before each key's expiration date to maintain uninterrupted access.
API keys cannot renew or extend in place. Each rotation requires creating a new key. An expired key returns an unauthorized error until the integration switches to a replacement.
Use a dedicated, least-privilege user account to generate automated keys rather than an account owner's credentials. See the developer API documentation for endpoint details and authentication requirements.
Comments
4 comments
Hello - There is a bad link on this page…I think it has an extra space character causing a bad redirect.
See the developer API documentation for more details.
Thanks, Mike S —copy and paste got the best of me there! All fixed, and thanks for helping make our docs better 💖
How can someone create an automated method of renewing API Keys if you have to login via the portal to get one? The API itself seems to provide the ability to create keys, but you need a key to use the API, so there seems to be a chicken and egg problem there.
Great question, Robert Gagnon! You've identified the bootstrapping catch correctly, and it's a real consideration for automation workflows.
The short answer: one manual step is unavoidable at the start. You'll need to generate your first API key through the dashboard and store it securely. From there, you can automate all future renewals — using the active key to create a replacement before it expires, updating your integration or secret store with the new key, validating it, then revoking the old one.
A couple of things worth keeping in mind:
We've actually just added an Automate API key renewal section to this article — it walks through the full rotation workflow. And for endpoint details and authentication requirements, the developer API docs are your best reference.
Please sign in to leave a comment.