<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Securing the Account API key in Workato Pros Discussion Board</title>
    <link>https://systematic.workato.com/t5/workato-pros-discussion-board/securing-the-account-api-key/m-p/1578#M631</link>
    <description>&lt;P&gt;We are using the Recipe Lifecycle Management APIs for our CI/CD process. However, as you all know the API key (from Settings) not only gives access to the RLM APIs, but to all the other Workato APIs (essentially all recipe ops), which essentially is very powerful. &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;Any ideas on how we can limit the exposure? IP Whitelisting for the API key, the same as we have in the API Platform? Or limit the exposed APIs and have multiple keys? &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;Anyone from Workato with any suggestions? &lt;SPAN id="mob-widget-1634769960119" class="mention"&gt;Tridivesh Sarangi&lt;/SPAN&gt; , &lt;SPAN id="mob-widget-1634769965477" class="mention"&gt;Deven Maru&lt;/SPAN&gt; &lt;/P&gt;</description>
    <pubDate>Thu, 21 Oct 2021 05:46:31 GMT</pubDate>
    <dc:creator>mroldanvega</dc:creator>
    <dc:date>2021-10-21T05:46:31Z</dc:date>
    <item>
      <title>Securing the Account API key</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/securing-the-account-api-key/m-p/1578#M631</link>
      <description>&lt;P&gt;We are using the Recipe Lifecycle Management APIs for our CI/CD process. However, as you all know the API key (from Settings) not only gives access to the RLM APIs, but to all the other Workato APIs (essentially all recipe ops), which essentially is very powerful. &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;Any ideas on how we can limit the exposure? IP Whitelisting for the API key, the same as we have in the API Platform? Or limit the exposed APIs and have multiple keys? &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;Anyone from Workato with any suggestions? &lt;SPAN id="mob-widget-1634769960119" class="mention"&gt;Tridivesh Sarangi&lt;/SPAN&gt; , &lt;SPAN id="mob-widget-1634769965477" class="mention"&gt;Deven Maru&lt;/SPAN&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 05:46:31 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/securing-the-account-api-key/m-p/1578#M631</guid>
      <dc:creator>mroldanvega</dc:creator>
      <dc:date>2021-10-21T05:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Securing the Account API key</title>
      <link>https://systematic.workato.com/t5/workato-pros-discussion-board/securing-the-account-api-key/m-p/1579#M632</link>
      <description>&lt;P&gt;Hi &lt;A href="https://systematic.workato.com/workato-migration/users/2373552"&gt;Manuel Roldan-Vega&lt;/A&gt; &lt;/P&gt;&lt;BR /&gt;&lt;P&gt;Agree on broad scope of the single key giving access to all APIs. We have scoping feature in the roadmap where you will be able to generate multiple keys for different sets of features. Let me look into the details and the plan.&lt;/P&gt;&lt;BR /&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;Deven&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 11:27:26 GMT</pubDate>
      <guid>https://systematic.workato.com/t5/workato-pros-discussion-board/securing-the-account-api-key/m-p/1579#M632</guid>
      <dc:creator>deven-maru</dc:creator>
      <dc:date>2021-10-21T11:27:26Z</dc:date>
    </item>
  </channel>
</rss>

