Frequently Asked Questions
Yes. You can generate multiple API Key–Secret pairs for your application, subject to the following conditions:
• A maximum of 3 active API keys is allowed per application.
• Each API key is valid for 13 months.
• When a new API key is generated, the existing key remains active for 60 days before being automatically revoked.
• The Add Key option is available only when all eligibility requirements are met.
Your API key is valid for 13 months from the date it is generated.
Yes. During API key generation, you can choose to align the API key expiry date with your SSL certificate expiry date.
No. API key generation is allowed only if your SSL certificate has more than one month of remaining validity.
• A new API Key–Secret pair is created.
• The new key is valid for 13 months.
The Add Key option is displayed only when:
• All subscribed API products are approved.
• Your SSL certificate is approved.
• Your application has fewer than 3 active API keys.
If any of these conditions are not met, the Add Key option will not be available.
Yes. You will receive weekly reminder notifications starting 60 days before your API key expires.
No. Existing API keys cannot be extended. You must generate a new API key when your current key is nearing expiry.
Yes. You can have a maximum of 3 active API keys for a single application at any given time.
You should generate a new API key before your current key expires to avoid any disruption to API transactions. Reminder notifications will be sent starting 60 days before expiry.
Once your API key expires, API requests using that key will no longer be authenticated. You must generate and use a valid API key to continue accessing APIs.
Yes. Your old API key remains active for 60 days after a new key is generated, allowing sufficient time to update your applications and systems.
Yes. You should update your application configuration with the newly generated API key and secret before the 60-day transition period ends.
Yes. If your application meets all eligibility criteria, you can generate a new API key without modifying other application configurations.
Each application can have a maximum of 3 active API keys at any given time.
If you have already reached this limit and need to generate a new API key, you must first revoke or delete one of the existing active API keys. Once the number of active API keys falls below the maximum limit, the Add Key option will become available, provided all other eligibility requirements are met.
Note: It is recommended to ensure that the API key being revoked or deleted is no longer in use before proceeding with the action.
When an API key reaches its expiry date, it is automatically marked as Revoked and can no longer be used for API transactions.
Any API requests made using the expired key will fail authentication. To avoid service disruption, you should generate a new API key and update your applications before the existing key expires.
Note: The system sends weekly reminder notifications starting 60 days before the API key expiry date to help you plan and complete the key rotation process in advance.
When you update certain application attributes (such as SSL certificate, IP whitelist, product subscription, or scope), the system will ask whether you would like to generate a new API key.
- If you select "Yes":
- A new API Key–Secret pair is generated.
- The new key is valid for 13 months.
- Your existing API key remains active for 60 days to allow a smooth transition.
- The old key is automatically revoked after the 60-day transition period.
- If you select "No":
- You will be redirected to create a new application.
- All application details and configurations must be entered again.
- A new API Key–Secret pair will be generated for the newly created application.
This ensures uninterrupted access while allowing you to choose the most suitable key rotation approach for your application.