Skip to content

Cookie preferences

We use cookies for our own analytics, to see how our campaigns perform and, if you allow it, to load content from other services such as the Google site search. We never sell your data. Necessary cookies keep the site working and cannot be switched off. See our Cookie Policy for details and our Privacy Policy for how we handle personal data.

Security, load balancing and remembering your cookie choice.

Show us which pages people read and how they find the site, so we can improve it (Google Analytics).

Show us which of our ad campaigns bring visitors to the site and remember the campaign or partner link you arrived from (Google Ads, partner program). We do not use these cookies to build advertising profiles.

Load the site search from Google when you use it. Google sets its own cookies and shows ads in the search results.

© 2026 The ThingsBoard Authors
Try for free

ThingsBoard Cloud

Choose your data region

Your data stays in the region you choose, for residency and compliance. No credit card required.

Rather run it yourself? Install on your own servers

API Keys

API keys provide a simpler alternative to password-based authentication for the ThingsBoard REST API. Unlike JWT tokens, which require a login request and expire periodically, API keys are long-lived credentials that remain valid until they expire or are manually revoked.

Feature Description
No login required API keys work immediately without exchanging a username and password.
Long-lived They stay valid until the expiration date you set.
Permission inheritance The key inherits the same permissions as the user it was created for.
Easy management Enable, disable, or delete a key at any time.
Simple integration Ideal for third-party apps, scripts, and MCP servers where you want to avoid complex authentication code.

API keys can be created for your own account or for other platform users, depending on your permissions.

  1. Click your profile name in the bottom-left corner and select Account.
  2. Navigate to the Security tab.
  3. In the API keys section, click the Manage button.
  4. Click the + Generate button.
  5. Enter a description for the API key (e.g., Production server, Testing environment).
  6. Select the expiration period.
  7. Click Generate.

A system administrator can create API keys for users of any tenant; a tenant administrator can create them for their customer users.

  1. Navigate to the Customers & users ⇾ Users section.
  2. Click the desired user to open their details.
  3. Go to the API keys tab.
  4. Click the + Generate button.
  5. Enter a description for the API key.
  6. Select the expiration period.
  7. Click Generate.

Include the API key in the X-Authorization header with the ApiKey prefix:

X-Authorization: ApiKey $YOUR_API_KEY_VALUE

Example:

Terminal window
curl -X GET --header 'Accept: application/json' \
--header 'X-Authorization: ApiKey $YOUR_API_KEY_VALUE' \
'https://$THINGSBOARD_HOST_NAME/api/auth/user'

Replace $YOUR_API_KEY_VALUE with your API key and $THINGSBOARD_HOST_NAME with your ThingsBoard hostname.

When using Swagger UI, you can authenticate with an API key:

  1. Open Swagger UI.
  2. Click the Authorize button.
  3. In the API key form (apiKey) section, enter your API key value with the ApiKey prefix:
    ApiKey YOUR_API_KEY_VALUE
  4. Click Authorize.

Each API key in the table displays:

Column Description
Created time When the API key was generated.
Description The description assigned to the key.
Status Whether the key is active or disabled.
Expiration time The date and time when the key will expire.

Available actions for each API key:

  • Enable / disable — use the toggle to temporarily disable or re-enable a key.
  • Delete — click the delete icon to permanently remove a key. This action cannot be undone.
  • Edit description — click the edit icon to update the key’s description.