Skip to main content
The API section lets you manage the API tokens used to authenticate with the LILT API. API keys are managed in Manage → API. This page is available to Admins and Customer Admins. Screenshot 2026 10 01 At 1 02 48 Pm

Legacy API Key

Your original API key is displayed at the top of this section. This key continues to work as before and is not affected by the introduction of API tokens. Screenshot 2026 10 01 At 1 04 08 Pm

Individual API Tokens

The API Tokens section allows you to create and manage multiple named tokens for different integrations. This is useful when you connect several systems to LILT (e.g., a CMS connector, a CI pipeline, and an internal tool) and want to manage each one independently. Creating a token
  1. Click Create Token.
  2. Enter a descriptive name (e.g., “Contentful connector”).
  3. Select who this token is for. Typically this will be the token creator but could be another customer contact or admin
    The API key permissions will match the permissions of the user role being assigned that key.
  4. Optionally set an expiration date.
  5. Click Create. The full token is displayed once — copy it immediately and store it securely. It cannot be retrieved later.
Screenshot 2026 05 26 At 7 00 39 Pm
Managing tokens The token list shows each token’s name and status, owner, prefix (e.g., lilt_abc1...), creation date, expiry date and when it was last used. Status is shown as a badge: Active (green), Expired (gray) or Revoked (red). By default, the list shows Active tokens only. Search: Use the search field to find a token by name, owner or key. Click ✕ to clear the search. Filter: Click Filters to show Active, Expired or Revoked tokens. Applied filters appear as chips you can remove. Sort: Sort by creation date, expiry date or last used date, ascending or descending. Tokens expiring within 30 days show their expiry date in orange; expired tokens show it in red. Actions:
  • Rotate (active tokens): generates a new secret while keeping the same configuration.
  • Revoke (active tokens): permanently disables the token.
  • Delete (expired or revoked tokens): removes the token from your list. You’ll be asked to confirm. Active tokens can’t be deleted — revoke them first. Screenshot 2026 10 01 At 2 35 49 Pm
Best Practices for API Keys Generate one API key per user per application. For example
  1. Each connector has it’s own API key
  2. Each user gets their own API key (e.g. if I’m using an API key for some sort of integration, I generate a new API key)
  3. You can only access/copy an API key at the time of creation. You can’t go back and copya key after it’s been initially generated.
  4. Temporary uses should have temporary keys but connectors should have non-expiring keys or expiration dates long in the future (because of the risks of connector API keys expiring)
  5. Regularly delete expired and revoked tokens to keep your list easy to manage.
  6. Sort by expiry date to find tokens that are about to lapse, and rotate them before they expire.
API tokens use the same authentication methods (?key= query parameter or Basic Auth) as the legacy key, so no changes are needed in existing SDKs or CMS plugins. For more information, see our API documentation.