# API keys

> Create an API key so that another system can read and write in Awrora.



If you have a developer, or a system that needs to read from and write to Awrora, there's an open API. With it, another system can, among other things, fetch experiences and available places, create and cancel bookings, manage customers and read gift cards. The API is in beta.

<Callout type="info" title="Included in the paid plans">
  The API and webhooks are included from the Bas plan. On Free, the **New API key** button is greyed out. Read more in [Plans and billing](/settings/plans-and-billing). There's no app to install — the API opens when you create your first key.
</Callout>

## Create an API key

<Steps>
  <Step title="Open For developers">
    Go to <Path>Settings → Apps</Path>, scroll down to **For developers** and click **API keys and webhooks**.
  </Step>

  <Step title="Create the key">
    Click **New API key**. Under **Name**, give the key a name you'll recognise, for example "Accounting export".
  </Step>

  <Step title="Choose permissions">
    Tick what the key is allowed to do under **Permissions**. All read permissions are selected by default. Permissions that change something are marked **can change data** — such as **Create and cancel bookings** — and you have to select those yourself. The key needs at least one permission. Then click **Create API key**.
  </Step>

  <Step title="Copy the key straight away">
    The **Your new API key** dialog shows the key only once. Copy it and hand it to whoever is going to use it. If you lose it, create a new one.
  </Step>
</Steps>

<Screenshot id="api-nyckel-ny" alt="The New API key dialog with the Name field and the list of permissions" />

## Who can do what

Only the organisation's owner can create and revoke keys. Administrators can see the list of keys, their permissions and when they were last used. Other users can't see the keys at all.

The list only shows keys that you have created yourselves. Keys that an app, such as [Zapier](/apps/zapier), uses for its connection are managed by the app and aren't shown here.

## Revoke a key

A key gives access to your company's data, so treat it like a password. When it's no longer needed, open the menu on the key's row, choose **Revoke** and confirm with **Revoke API key**. All requests using the key stop working immediately and it can't be undone. The key stays in the list as **Revoked**.

<Cards>
  <Card title="API guide" href="/developers" icon="terminal">
    Get started with the API: authentication, error codes, limits and webhooks.
  </Card>

  <Card title="API reference" href="/api-reference" icon="code">
    Every request, field and response in detail.
  </Card>
</Cards>
