MyLeadFox

Account and team

Create and rotate API keys

A key can be limited to only what the thing using it actually needs, so a reporting script never has the ability to spend your export or enrichment allowance.

  1. Open your API keys

    Everyone on the account can see which keys exist. Only the account owner can create, rotate or revoke one.

  2. Name it for where it will be used

    A name like the system it lives in is what makes a key safe to revoke later without wondering what will break.

  3. Give it only the scopes it needs

    Keys can be scoped to search, download and enrich independently. A key that only reads should not carry the scopes that spend.

  4. Restrict it to your addresses

    Optionally limit the key to specific IP addresses or ranges, so a leaked key is unusable from anywhere else.

  5. Copy the secret now

    The secret is shown once, at creation, and is never retrievable afterwards. Only a name and the last few characters are ever displayed again.

  6. Rotate or revoke when you need to

    Rotating issues a new secret and stops the old one. Revoking stops the key while keeping your download history’s record of what it did.

Worth knowing

  • The account owner is emailed whenever a key is created, rotated or revoked, so a key issued without their knowledge is visible immediately.
  • Rate limits apply per key and are the same on every plan.

Try this on the real database

Free trial with the full dataset and every filter, and the allowance resets daily rather than expiring.