Skip to main content
To start using the Webacy DD APIs, you’ll need an API key associated with your account. Your API key authenticates requests to Webacy and determines which products, usage limits, and environments your account can access.
1

Create an account

Create an account on our Developer Portal or sign in to your existing account.
The Developer Portal requires a work or organization email address to register. Personal addresses such as Gmail, Yahoo, or Outlook are rejected during sign-up with the error Please use your organization's email address to register. Personal email addresses are not permitted. If you do not have an organization email, contact info@webacy.com to request access.
Screenshot 2026 07 30 At 4 43 06 PM
2

Navigate to API Keys

Once you are signed in, open the developer dashboard and navigate to API Keys.
Screenshot 2026 07 30 At 4 44 23 PM
3

Generate your API key

From the API Keys page:
  1. Select + Generate API Key.
  2. Securely store the generated key.
Screenshot 2026 07 30 At 4 47 49 PM
4

Start Testing!

Keep Your Key Secure!Treat your API key like an important password.Do not:
  • expose it in browser-side code
  • commit it to a public repository
  • include it in screenshots, logs, or support messages
  • share the same production key across unrelated applications
If your key is exposed, anyone can use your API key as you. You will be responsible for all usage costs, limits, and impact caused by the exposed API key.
Use Separate Keys for Each EnvironmentWe recommend creating different keys for:
  • local development
  • staging
  • production
  • separate applications or internal teams
This makes it easier to monitor usage, rotate compromised credentials, and revoke access without interrupting every integration.

Rotate or revoke your key

Self-service rotation and revocation are not yet available in the Developer Portal (see the coming-soon list below). Until they ship, use the following interim workflow. To rotate a key:
  1. In the Developer Portal, open API Keys and select + Generate API Key to create a new key.
  2. Update every application, environment, and stored secret to use the new key.
  3. Stop sending the old key. Requests with the old key continue to succeed until Webacy revokes it, so cut all traffic over before requesting revocation.
To revoke a key, including any key you believe is compromised:
  1. Complete the rotation steps above so live traffic is on the new key.
  2. Email info@webacy.com or use the contact form with the key ID (never the full secret) and request revocation. Webacy revokes the key on your behalf.
If a key is exposed, treat it as compromised. Rotate first so your integration keeps working, then request revocation immediately. The old key remains valid until Webacy revokes it.

🚧 Under Construction 🚧

Our Developer Portal is currently under construction. The following features are coming soon:
  • Rotate API Key
  • Revoke / Delete API Key
  • Create Multiple API Keys
  • Team Management 
  • RBAC
Want additional features? Contact Us.

What’s Next

Authentication

Learn how to authenticate your API requests