User access keys
User access keys in Nobl9 are user personal access keys intended for authenticating programmatic requests made with:
We are phasing out the old term Access keys in favor of User access keys for better clarity. As part of this, we are replacing the /settings/keys path with /settings/user-access-keys.
The old path will redirect to the new one and is planned to be phased out in March 2026.
Managing user access keysβ
You can manage all your keys from the Settings > My user access keys tab in the Nobl9 web application. Each user can have a maximum of two access keys at a time, including any disabled (inactive) keys.
To create a key:
-
Go to Settings > My user access keys and click Create user access key.
-
(Optional) Add a Description to help you identify the key later.
-
Securely store the Client ID and Client Secret.
Client secret one-time displayThe Client secret is only displayed once. Ensure you save it or the configuration TOML before closing the window.
-
Click OK. Your key is now created and active.
You can temporarily disable a key to suspend requests made with it or delete it completely. For this:
- Go to Settings > My user access keys.
- Locate the key you want to manage.
- Select the required optionβDisable or Delete.
Key points:
- A disabled key is inactive but still counts toward your two-key limit.
- Deleting a key is permanent and cannot be undone.
- Any applications of scripts using a disabled or deleted key will fail.
- You can enable a disabled key at any time to resume authenticating with it.
Managing user access keys in your organizationβ
Users with the Organization Admin role can review and control the user access keys of everyone in the organization. For this, go to the Settings > All user access keys tab.
The list contains every key that belongs to a user who can sign in to Nobl9. Keys of deactivated users are not listed, as such keys no longer authenticate. For each key, the list shows:
- Owner and Email of the user the key belongs to
- Client ID
- Description added by the owner
- Status: Active, Inactive, or Expired
- Created and Expires dates
Keys with no expiration date show Never
Key secrets are never displayed or exported.
To find a key:
- Search by owner name, email, or client ID.
- Filter the list by key status.
- Sort by the Created or Expires column.
When sorting by Expires in descending order, keys that never expire come first.
To save the list, click Export as CSV. The export includes every key that matches the current search and filters, not only the rows currently displayed.
To restrict a key, change its status in the Status column or delete it with the row action:
- Disabling a key stops all requests made with it. You are asked to confirm, because any automation that uses the key will fail. You can enable a disabled key at any time.
- Deleting a key is permanent and cannot be undone.
- Expired keys cannot be enabled.
Every status change and deletion made from this tab is recorded in the organization audit log. Key owners keep full control over their own keys under My user access keys.
As an Organization Admin, you cannot:
- View or recover a key secret
- Create a key on behalf of another user
- Edit another user's key description
- Change the owner of a key
Key expirationβ
By default, user access keys in Nobl9 do not expire. However, you can request to have an automatic expiration policy enabled for your organization to enforce key rotation.
- This setting applies to all newly created keys within your organization.
- It does not affect keys that already exist. To enforce the policy on all keys, you must manually delete and recreate any keys that were generated before the policy was enabled.
When a key expires, any requests signed with it will fail. Ensure you rotate your keys before they expire to maintain a seamless operation.