This guide explains how to create, rotate and revoke API keys in the Fuuse portal, so you can connect Fuuse data to your own systems without contacting support.
Contents:
- Before you start
- Open API Management
- Create an API key
- Copy and store your key
- Understand the API keys table
- Rotate an API key
- Revoke an API key
- Use your key with the Fuuse Public API
1. Before you start
API keys let your own software, fleet tools or third-party platforms read (and, where allowed, update) your Fuuse data through the Fuuse Public API. Each key has:
- a name, so you can recognise it later;
- an operator scope, which controls which organisations' data it can access; and
- a set of permissions, which control which services it can use and what it can do with them.
API Management is found under the "Organisation" menu, so you'll need a portal account with access to that menu (for example, an administrator). If you can't see "API Management", ask your portal administrator, or contact the Fuuse support team and we'll check whether it's enabled for your organisation.
2. Open API Management
- In the left-hand menu, browse to "Organisation" › "API Management".
- The page shows a table of all API keys for your organisation, a "Create API Key" button and an "API Docs" button, which opens the Fuuse Public API documentation in a new tab.
3. Create an API key
Creating a key takes three short steps. You can select "Back" at any point to change an earlier step, or "Cancel" to close without creating anything.
Step 1 – Key details
- Select "Create API Key".
- In "Key name", enter a label that will help you recognise the key, for example "Fleet Integration". This name is only shown in the portal; it isn't visible to the API.
- Select "Next".
Step 2 – Operator scope
Choose which organisations' data the key can access:
| Option | What it means |
|---|---|
| "This operator only" | The key can only access data for the organisation you're currently logged in to. This is the right choice for most customers. |
| "All child organisations" | For parent organisations. The key can access all of your current child organisations, and any you add in the future automatically. |
| "Select specific child organisations" | For parent organisations. Choose one or more child organisations from the list. This list is fixed when the key is created – child organisations added later are not included. |
- Select the option you need. If you chose "Select specific child organisations", tick at least one organisation in the list.
- Select "Next".
Tip: if you see "No child organisations available", your organisation doesn't have any child organisations – choose "This operator only" instead.
Step 3 – Permissions
You'll see a list of API services (for example Sessions, Locations, Drivers or Tariffs), each with a short description and the permission levels available for it. Tick only the permissions your integration actually needs.
| Permission | What it allows |
|---|---|
| Read | View data from that service, such as charging sessions or site locations. |
| Write | Create and update records, such as adding a driver or updating an RFID card. |
| Manage | Destructive or bulk actions, such as deleting a driver. Only grant this if you're sure it's needed. |
Not every service offers every permission level – you'll only see the options that apply.
- Tick at least one permission.
- Select "Create Key".
Note: you can't change a key's permissions or operator scope after it's been created. If you need different access later, create a new key and revoke the old one.
4. Copy and store your key
As soon as your key is created, a window titled "Your API key has been created" shows the full key.
Important: this is the only time your key will be shown. Fuuse can't retrieve it for you later, so copy it now and keep it somewhere secure, such as a password manager or your system's secrets store.
- Select "Copy" to copy the key to your clipboard.
- Paste and save the key somewhere secure.
- Tick "I have copied and stored my API key safely."
- Select "Done". Your new key now appears in the table.
If you lose a key, you can't view it again – rotate it to get a new one instead.
5. Understand the API keys table
| Column | What it shows |
|---|---|
| Name | The key name you entered. |
| Status | "Active" (the key works) or "Revoked" (the key no longer works). |
| Operator scope | "This operator", "All child organisations" or "Selected organisations". |
| Permissions | Each service the key can use and its permission levels, for example "Sessions · Read". If a key has more than five services, select the "+[number] MORE SERVICES" link to see them all. |
| Created | The date the key was created. |
| Expiry | The date the key expires. A dash (—) means the key has no expiry date. |
To rotate or revoke an active key, open the actions menu (…) at the end of its row. Revoked keys have no actions.
6. Rotate an API key
Rotating replaces a key with a brand-new one that has the same permissions and operator scope. Use it if a key may have been exposed, if you've lost it, or as part of regular security housekeeping.
Important: the old key stops working immediately. Any integration using it will fail until you update it with the new key, so plan the change with whoever manages that integration.
- In the API keys table, open the actions menu (…) on the key and select "Rotate".
- Read the warning, then select "Rotate key".
- A window titled "Your API key has been rotated" shows the new key. Copy and store it as described in section 4, tick the confirmation box and select "Done".
- Update your integration with the new key.
7. Revoke an API key
Revoking permanently switches a key off. Use it when an integration is no longer needed or if you think a key has been compromised.
- In the API keys table, open the actions menu (…) on the key and select "Revoke".
- Read the warning, then select "Revoke key".
- You'll see a confirmation message, and the key's status changes to "Revoked".
A revoked key stops working immediately and can't be reactivated. It stays in the table as "Revoked" for around 30 days and is then permanently deleted. If you need access again, create a new key.
8. Use your key with the Fuuse Public API
Select "API Docs" on the API Management page, or visit developer.fuuse.io/v2, for details of the available endpoints and how to authenticate your requests with your key.
A few good habits:
- Create a separate key for each integration, so you can rotate or revoke one without affecting the others.
- Give each key only the permissions it needs.
- Never share keys by email or chat, or store them in code repositories.
Note: if something goes wrong while creating, rotating or revoking a key, the portal may show an error ID. Please contact the Fuuse support team and include that error ID so we can investigate quickly. API usage logs are coming in a future update.