Software Secure Workload
Activity Configure

Generate API Key and Secret

Procedure

1

In the upper right corner of Secure Workload UI, click the logged in account and choose API Keys.

2

Click Create API Key.

3

(Optional) Enter a description for the API key.

4

Select the required capabilities for the API key and API Secret.

A limted set of capabilities are available for using the API Key and API Secret pair.

The availability of the API capabilities varies based on the user role. The following API capabilities are available for all user roles.

Table 1. API Capabilities

Capability

Description

sensor_management

To configure and monitor the status of software agents.

software_download

To download software packages for agents or virtual appliances.

flow_inventory_query

To query flows and inventory items in the Secure Workload cluster.

user_role_scope_management

To read, add, modify, remove users, roles, and scopes.

user_data_upload

To allow users to upload data for annotating flows and inventory items or upload good or bad file hashes.

app_policy_management

To manage workspaces (applications) and enforce policies.

external_integration

To allow integration with external systems such as vCenter and kubernetes.

The following API capabilities are available only for the Site Administrators.

Table 2. API Capabilities for Site Administrators

Capability

Description

appliance_management

To manage Secure Workload appliance

appliance_monitoring

To monitor Secure Workload appliance settings and configurations (read-only)

5

Click Create.

API key and secret are generated and must be copied to a file, and saved in a safe location. Alternatively, you can download the JSON file with the key and secret.

 

If External Auth with LDAP and LDAP Authorization are enabled, API Key access to Open API stops because Secure Workload roles from LDAP member of groups are reassessed after the user session ends. To avoid interruptions, enable the Use Local Authentication option in the Edit User Details for users with API keys.