api_keys
Creates, updates, deletes, gets or lists an api_keys resource.
Overview
| Name | api_keys |
| Type | Resource |
| Id | fivetran.users.api_keys |
Fields
The following fields are returned by SELECT queries:
- get
- list
| Name | Datatype | Description |
|---|---|---|
user_id | string | The unique identifier for the user within the Fivetran system. (example: user_id) |
created_at | string (date-time) | The timestamp that the user created their API key (example: 2024-01-01T00:00:00Z) |
expires_at | string (date-time) | The timestamp when the API key expires. (example: 2024-04-01T00:00:00Z) |
key_status | string | The status of the API key. Possible values: ACTIVE: The key has a single active secret, ACTIVE_GRACE: The key has two active secrets during rotation overlap, and EXPIRED: The key has expired. (ACTIVE, ACTIVE_GRACE, EXPIRED) (example: ACTIVE) |
key_value | string | The public identifier of the API key. (example: key_abc123) |
last_rotated_at | string (date-time) | |
overlap_expires_at | string (date-time) | The timestamp when the previous secret expires after rotation. Only present during the overlap period. (example: 2024-03-08T00:00:00Z) |
user_type | string | The type of user. Possible values: REGULAR_USER: A human user who can log in to the Fivetran dashboard and interact with the API, and SERVICE_ACCOUNT: A non-human identity for machine-to-machine API access that cannot log in to the dashboard. (REGULAR_USER, SERVICE_ACCOUNT) (example: SERVICE_ACCOUNT) |
| Name | Datatype | Description |
|---|---|---|
user_id | string | The unique identifier for the user within the Fivetran system. (example: user_id) |
created_at | string (date-time) | The timestamp that the user created their API key (example: 2024-01-01T00:00:00Z) |
expires_at | string (date-time) | The timestamp when the API key expires. (example: 2024-04-01T00:00:00Z) |
key_status | string | The status of the API key. Possible values: ACTIVE: The key has a single active secret, ACTIVE_GRACE: The key has two active secrets during rotation overlap, and EXPIRED: The key has expired. (ACTIVE, ACTIVE_GRACE, EXPIRED) (example: ACTIVE) |
key_value | string | The public identifier of the API key. (example: key_abc123) |
last_rotated_at | string (date-time) | |
overlap_expires_at | string (date-time) | The timestamp when the previous secret expires after rotation. Only present during the overlap period. (example: 2024-03-08T00:00:00Z) |
user_type | string | The type of user. Possible values: REGULAR_USER: A human user who can log in to the Fivetran dashboard and interact with the API, and SERVICE_ACCOUNT: A non-human identity for machine-to-machine API access that cannot log in to the dashboard. (REGULAR_USER, SERVICE_ACCOUNT) (example: SERVICE_ACCOUNT) |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | user_id | Returns the API key details for the specified service account. | |
list | select | cursor, limit, user_type | Returns a paginated list of API keys for all users within your Fivetran account. | |
create | insert | user_id | Creates a new API key for the specified service account. The secret is<br />returned once at creation and cannot be retrieved again.<br /><br />> Note: Only a regular user can perform this operation.<br /> | |
delete | delete | user_id | Deletes all API keys for the specified user.<br /><br />> Note: Only a regular user can perform this operation.<br /> | |
rotate | exec | user_id | Rotates the API key for the specified service account and generates a new secret.<br /><br />During the optional overlap period, both the old and new secrets remain valid, allowing zero-downtime credential rotation.<br /><br />> Note: Only a regular user can perform this operation.<br /> |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
user_id | string | The unique identifier for the user within the account. |
cursor | string | Paging cursor, [read more about pagination](https://fivetran.com/docs/rest-api/pagination) |
limit | integer (int32) | Number of records to fetch per page. Accepts a number in the range 1..1000; the default value is 100. |
user_type | string | The type of user. Possible values: REGULAR_USER: A human user who can log in to the Fivetran dashboard and interact with the API, and SERVICE_ACCOUNT: A non-human identity for machine-to-machine API access that cannot log in to the dashboard. |
SELECT examples
- get
- list
Returns the API key details for the specified service account.
SELECT
user_id,
created_at,
expires_at,
key_status,
key_value,
last_rotated_at,
overlap_expires_at,
user_type
FROM fivetran.users.api_keys
WHERE user_id = '{{ user_id }}' -- required
;
Returns a paginated list of API keys for all users within your Fivetran account.
SELECT
user_id,
created_at,
expires_at,
key_status,
key_value,
last_rotated_at,
overlap_expires_at,
user_type
FROM fivetran.users.api_keys
WHERE "limit" = '{{ limit }}'
AND user_type = '{{ user_type }}'
;
INSERT examples
- create
- Manifest
Creates a new API key for the specified service account. The secret is<br />returned once at creation and cannot be retrieved again.<br /><br />> Note: Only a regular user can perform this operation.<br />
INSERT INTO fivetran.users.api_keys (
expiration_period_days,
user_id
)
SELECT
{{ expiration_period_days }},
'{{ user_id }}'
RETURNING
created_at,
expires_at,
key_secret,
key_status,
key_value
;
# Description fields are for documentation purposes
- name: api_keys
props:
- name: user_id
value: "{{ user_id }}"
description: Required parameter for the api_keys resource.
- name: expiration_period_days
value: {{ expiration_period_days }}
description: |
The number of days until the API key expires. Defaults to 90. Maximum is 365.
DELETE examples
- delete
Deletes all API keys for the specified user.<br /><br />> Note: Only a regular user can perform this operation.<br />
DELETE FROM fivetran.users.api_keys
WHERE user_id = '{{ user_id }}' --required
;
Lifecycle Methods
EXEC variables use wire (API) names.
- rotate
Rotates the API key for the specified service account and generates a new secret.<br /><br />During the optional overlap period, both the old and new secrets remain valid, allowing zero-downtime credential rotation.<br /><br />> Note: Only a regular user can perform this operation.<br />
EXEC fivetran.users.api_keys.rotate
@user_id='{{ user_id }}' --required
@@json=
'{
"expiration_period_days": {{ expiration_period_days }},
"overlap_days": {{ overlap_days }}
}'
;