惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

有赞技术团队
有赞技术团队
M
MIT News - Artificial intelligence
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
量子位
S
SegmentFault 最新的问题
V
Visual Studio Blog
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
Stack Overflow Blog
Stack Overflow Blog
Vercel News
Vercel News
D
Docker
J
Java Code Geeks
博客园 - 三生石上(FineUI控件)
博客园 - Franky
Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
Y
Y Combinator Blog
云风的 BLOG
云风的 BLOG
V
V2EX

Buttondown's blog

Email could have been X.400 times better The physicists who convinced Fermilab to send Brazil's emails Better in-app previews Analytics 3.0 Subscriber ID variables Comments! Send latest premium action Automation filtering Free API subscribers Surveys in automations Reply to replies Labels for RSS feeds How Jeremy Singer-Vine curates curious datasets for readers 2023 (and what's next) Email vs web content Sort by engagement Better gift subscriptions How Andy Dehnart built a career reviewing television New email template Email-based automations Opt-in reply tracking Automatic alt text More social network integrations Sort by metadata Overlarge image warnings Automation tag actions Pause emails mid-flight Search tags and automations Gift via automations Subscriber-driving emails
Granular API keys
Justin Duke · 2026-01-24 · via Buttondown's blog

Create as many API keys as you need, each with its own permissions.

Justin Duke

Justin Duke

January 24, 2026

If you use the Buttondown API, you've probably run into this: you've got one API key, and it can do everything. That's fine when it's just you tinkering around, but once you start building real integrations — a Zapier workflow here, a custom script there, maybe a third-party tool that only needs read access — sharing the same all-powerful key everywhere starts to feel a bit risky.

Now you can create multiple API keys, each with its own permissions. Head to API → Keys and you'll see a new management page where you can:

FeatureDescription
Create as many keys as you needNo more sharing a single key across all integrations
Give each one a labelSo you remember what "api_key_7f3a" is actually for
Set granular permissionsControl exactly what each key can do

The permissions are pretty straightforward — for each category (subscribers, emails, automations, etc.) you can choose:

LevelAccess
WriteFull access to create, update, and delete
ReadCan view but not modify
NoneNo access at all

So if you're building a dashboard that just displays subscriber counts, give it a read-only key. If you're integrating with a third-party form tool, create a key that can only add subscribers. If something goes wrong with one integration, you can regenerate or delete that specific key without breaking everything else.

This is especially handy if you're working with contractors or external tools — you can give them exactly the access they need, nothing more.

Check out the API authentication docs for more details on how to use your keys.