Skip to main content
ORCA
MES
EN

Issue and manage Open API keys

This is the Open API setup procedure.

The ORCA team can assist with the integration if needed.

Before issuing a key

  • Sign in with the corporation master account.
  • A Pro plan or higher subscription is required.
  • Validation uses the issuing user; customer keys have no selectable or additional scopes.

Issue the key in ORCA

  1. Sign in to ORCA and open Integration Management → Open API Keys.
  2. Select Create key and enter a recognizable name and optional expiry.
  3. Copy the plaintext key after creation. You can copy it again later from API Key Management details.
ORCA Create API key modal with a key name entered and unlimited expiry selectedORCA API key created modal showing the plaintext key with a copy buttonORCA API key details modal showing the plaintext key with show/hide and copy controls

ORCA OPEN API key management →

Storage rules

  • Never store it in a browser, mobile app, public repository, or order database.
  • Never log the Authorization header or plaintext key.
  • If ownership changes or exposure is suspected, issue a replacement and revoke the old key.

List and revoke

The list shows name, prefix, status, created date, expiry, and last used date only.

Copy the original key again from details. Revocation takes effect immediately.

Revoked keys can be deleted from the list. Active keys must be revoked first.

If issuance fails, ORCA operators can inspect the corporation entitlement and key status in Master Admin.

ORCA API Key Management page listing name, prefix, status, created date, last used, and expiry

Next: Sales-order integration →