API Key Generation - Missing a generate/Create Button?

16 comments started 2023-09-20 last 2023-10-09
APIsHome Automation
N
#1 Northwarks

Hi All - I can't locate where to create my API key for HA access so I can use SMARTTARGET? I'm looking in >Account Settings>Manage Account Settings>My API Keys but I don't have a Generate/Create Option?

What am I missing?

#2 positor1

Northwarks >Account Settings>Manage Account Settings

then top right "manage account security"

N
#3 Northwarks

positor1

I'm sure there used to be an option to create a key here - or has that moved under API Tokens ?

M
#4 MTB

I am having the same issue. Can't find a way to generte an API key in the current interface...

#5 hoggy

MTB click Manage API Tokens button, they are all in there.
The "My API Keys" section is a bit of a red herring currently.

M
#6 MTB

hoggy OK thanks... So do I just cut and paste in the name of the token into Home Assistant then? It doesn't look much liek a traditional API key e.g.

#7 hoggy

MTB yes once you've generated one it'll just need copying and pasting into Home Assistant if your using it in PALM as far as i know (I don't use it)
it'll start "eyJ...."

M
#8 MTB

hoggy eyJ...."

Thanks, but there is no way I can find to make it display the actual key or token in that format. This is all I see in the portal interface under Account Settings. No generate API key there any more...

Click on "Manage Account Security", I get this (again, nothing in the key list and no way to generate a new key):

Clicking on "Manage givenergy.cloud API Tokens" gets me here...

I cannot do anything to modify or update those tokens once they are generated, nor can I see anythign in that format you mention. Time to consult Giv support maybe?

#9 hoggy

MTB if your not using the key then just delete it and generate another, it should just spit one out when you select all the scopes you want using the generate token button.
Failing that it used to send you the key to your email aswell, not sure it still does that or not. I'm on mobile now so can't check.

Y
#10 Yossarian

I'm having the same issue. Generate a token but then it won't display. Can't revoke either, get a 404 error

M
#11 MTB

hoggy Thanks for trying, but none of those actions seems to result in a key at present - indeed I can't delete an old key, as I've never previously needed to generate one! I've logged a support request with Giv, let's see what they say, I suspect it is a bug they will need to squish tbh...

W
#12 Whitzend

It looks like when you create a new API token you get a temporary message on the screen which allows you to copy the key but it's a one-time thing.

Agree that the delete token function leads to a 404 error and does not delete the token.

#13 Icarus

I raised this issue under the cloud portal topic recently:
See https://community.givenergy.cloud/d/3178-404-error-trying-to-revoke-a-givenergy-api-token
I also raised a defect ticket

It's actually quite serious (for me anyway) because I've created a token that has become publically exposed (quite accidentally) and I cannot revoke it, meaning my smart devices are potentially controllable by bad actors.

I've heard nothing from GivEnergy on the topic. It's feels like the management of these JWT tokens has not been thought out properly. I'm pretty dissapointed with the security issue.

#15 Icarus

In connection with the above defect, I'd also like to point out that once a bug report is given by feedback, the 'view' option just produces this:

Very frustrating.

#16 Icarus

I had a response from Fraser at GivEnergy HQ to say that developers are aware of the issue and are working on rectifying the problem. The implication from the message that the timescale might be a few days. I won't hold my breath.