Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/API & automation/Manage and secure API keys

Manage and secure API keys

LAST UPDATED

3 months ago

    A WP Cloud API key authenticates requests for one WP Cloud host client account. Create separate keys for separate uses, restrict each key to known static addresses and only the endpoints it needs, and store it as a secret.

    Manage keys in the Partner Portal or through Support

    Self-serve WP Cloud partners and managed partners with access to the WP Cloud Partner Portal manage keys in the portal’s API key management screen.

    Some managed partners do not yet have a Partner Portal account. In that case, contact WP Cloud Support to:

    • request a new key;
    • add, replace, or remove an allowed IP address or CIDR; or
    • change which API endpoints the key may access.

    Partners must also contact WP Cloud Support when an allowed CIDR range needs to be larger than /24.

    Configure a key

    Create separate keys for separate uses. Common examples include a production hosting panel, test automation, and an individual developer. Do not share one developer key across a team or reuse a production key for local development.

    The Partner Portal currently provides these settings when you create a key:

    • Key name. Use letters, numbers, and hyphens. The name must start with a letter.
    • Allowed endpoints. Enter one endpoint per line. New keys include default endpoint access unless you remove it. Keep only the access required by the key’s intended use.
    • Allowed IP ranges. Enter one IPv4 address or CIDR range per line. The portal treats a single IP address as /32 and accepts CIDR prefixes from /24 through /32.

    Good network sources include a static office gateway, an automation server, a bastion host, or a private VPN with stable egress addresses. Do not allow dynamic home addresses, consumer VPNs, or public Wi-Fi networks.

    Store and test the key

    Store the key in a secrets manager or another server-side credential store. Keep it out of source control, browser code, command history, application logs, and customer-facing error messages.

    WP Cloud API requests send the key in the Auth header:

    curl --fail-with-body --silent --show-error \
      --header "Auth: ${WP_CLOUD_API_KEY}" \
      "https://atomic-api.wordpress.com/api/v1.0/get-sites/${WP_CLOUD_CLIENT}/+"Code language: JavaScript (javascript)

    The List Client Sites endpoint is a useful read-only check when it is included in the key’s endpoint access. A successful request returns a data array. A 403 response means the key, source address, partner account, or endpoint access does not allow the request.

    Change, rekey, or revoke a key

    Assume that changes to a key take effect immediately. Changing its allowed endpoints or IP ranges, rekeying it, or revoking it can immediately interrupt every server, portal, application, or developer that relies on the key and its current configuration.

    For a planned rekey:

    1. Create a new key.
    2. Configure its allowed endpoints and IP ranges.
    3. Replace the old key in every server, portal, application, and developer environment that uses it.
    4. Verify that each integration works with the new key.
    5. Remove the old key.

    For an emergency involving a lost, exposed, or compromised key, revoke or rekey it immediately, then replace it everywhere it was used.

    Previous WP Cloud glossary
    Next Client SSH

    Related Guides

    • Client SSH

      Configure and secure Client SSH for partner developers, support teams, panels, and automation that need…

      5 Min.

      READ

    • WP Cloud API quick start

      Use the WP Cloud API to create and inspect sites, manage domains and certificates, change…

      14 Min.

      READ

    • Webhooks

      Configure WP Cloud webhooks, handle event payloads, and validate webhook signatures.

      4 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications