API keys
API keys are used to uniquely identify a user and protect APIs from unauthorized access. You or external service providers can use API tokens to access data and perform actions securely.
You can access the token overview with the shortcut GAK.
Since API keys allow direct access to protected data, you should always handle them carefully and never save them unsecured.
View Existing API Keys
- The permission
api_key__list
is required. - Go to Settings ➜ General ➜ API Keys.
- On the overview page, all existing API keys are displayed.
Tokens are organized according to their use:
- Admin API Keys
- CMS Internal Tokens
- Storefront API Keys
Depending on their use, API keys control access to certain areas and permissions. For details on the different rights, please contact your technical consultant.
The following information is displayed for each key:
- Last four characters of the key
- Creation date
- Scope of the resources
- Note (if added)

Overview API Keys
Generate API Keys
To generate a new API key in the SCAYLE Panel:
- The permission
api_key__create
is required. - Go to Settings ➜ General ➜ API keys.
- Click + Token.
- A window opens where you need to specify the following
- Resources (these refer to the endpoints/ entities the token should apply to)
- Operation Type (restricts the access token to read or read & write access)
- Token Name
- Description
- Additionally you can restrict the Token further based on specific companys, shops and/ or IP Address Filtering
When you generate a token, the creation date is automatically saved, and the key is then displayed. You can save it directly to your clipboard with a click on the copy button.
The created token will only be displayed once. If you leave the creation page, you will only see the encrypted token. It is no longer possible to view the complete API key.
As it is not possible to copy a token later, you may have to generate a new API key if necessary and then use this key.

Create a Token
Delete API Keys
API keys can be removed individually using the delete icon. The permission api_key__delete
is required for this action. Deleting an API key will immediately disable all access utilizing that key.
This action cannot be undone. Before deleting an API Key, please make sure that the token is no longer in active use.

Refer to API Credentials for details on how to access Checkout via API.