added

Security Enhancements to API Key Creation and Management

API Key Management Updates

Motive is updating the company's API key creation and management experience to make it more secure and give admins greater control over permissions, expiration, and data access. These enhancements help customers create safer integrations while reducing the risk associated with over-permissioned or long-lived API keys.

Read the documentation for creating an API key after these new updates.

New updates

Permissions and access

Earlier behaviorWhat's new
New API keys were created with broad access by default, making it difficult to limit a key to only the APIs and actions required by an integration.New API keys require explicit scopes. Admins can select the required permissions and review whether each scope provides read or manage access.

Expiration and rotation

Earlier behaviorWhat's new
API keys did not have a strong expiration and rotation workflow.New API keys require an expiration duration of up to six months. Keys expire automatically, and default admins receive an IMPORTANT Notification Center alert seven days before expiration.

Group-level data access

Earlier behaviorWhat's new
API keys could expose a broader set of company data than an integration needed.Admins can optionally restrict a new API key to specific Groups so it returns only the data associated with those Groups.

API key visibility

Earlier behaviorWhat's new
The full API key could remain visible after creation, increasing the risk of accidental exposure.The full key is shown only once in a copy modal immediately after creation. After the modal is closed, the key is masked and cannot be retrieved or copied again.

Key reactivation

Earlier behaviorWhat's new
Deactivated keys could be reactivated.Expired or deactivated keys cannot be reactivated. Admins must create a replacement key when renewed access is required.

Permission and Group changes

Earlier behaviorWhat's new
An existing key could continue to be used even when an integration's access requirements changed.Configure permissions and Groups when creating the key. If the configuration needs to change, create a replacement key with the required access.

API Access experience

Earlier behaviorWhat's new
API key details were managed in the legacy Developers experience.The new experience makes permissions, expiration, Group scope, and key status easier to review.

What this means for existing integrations

Existing API keys remain functional with their current broad compatibility during the initial rollout. The new scope, expiration, and Group requirements apply only to keys created after this update. Motive will communicate separately about any future migration plan for legacy keys.

Frequently asked questions

Will this update break my existing integrations?

No. Existing API keys continue to work with their current behavior during the initial rollout. The new creation requirements apply to new keys.

Can I view or copy a key after closing the copy modal?

No. The full key is shown only immediately after creation. The API Access list displays a masked value afterward.

What happens when a key expires?

The key is automatically expired and cannot be reactivated. Create a replacement key and update the integration before the current key expires.

Can I change a key's permissions or Groups later?

Create a replacement key when the integration needs different permissions or Group access. Configure the required scopes and Groups during creation.

Does this change apply to OAuth?

No. This update describes company API keys created from the Motive web dashboard. OAuth access is managed separately.