Keys and account access
Create a key
Section titled “Create a key”Open Developer API from the CSFolder account menu (/developers). The dashboard shows your current plan, monthly usage, request-per-minute ceiling and UTC reset date. All keys on that account share the same allowance.
- Give the key a name that identifies your app.
- Choose a project key for market data, or a personal key for selected portfolios.
- Select an expiry of 7, 30 or 90 days. Personal keys also require explicit portfolio selection and consent.
- Save the secret as the server-side
CSFOLDER_API_KEYenvironment variable. It is shown only once and hidden after five minutes or when you leave the tab. It cannot be recovered from the key list.
Creating or rotating credentials requires a sign-in within the last 30 minutes. If prompted, verify your sign-in and check the active CSFolder account. A copied documentation URL does not grant API access; requests need the bearer key.
Rotate or revoke
Section titled “Rotate or revoke”Rotate replaces the secret immediately and preserves its permissions and original expiry. The old secret stops working; update your app’s environment variable with the new secret. There is no overlap period.
Revoke permanently disables that key. It remains available from an older but still valid site session, so you do not have to reauthenticate just to remove access. Never paste the old or new secret into a support message or AI prompt.
The recent-activity list records key creation, rotation, revocation and changes to account access. It never contains secrets. The account ID shown in the dashboard can be used for support; it is not an authentication credential.
Plans and private data
Section titled “Plans and private data”The dashboard displays the allowance currently assigned to you. Manual entitlement changes do not charge a payment or create a subscription, and do not reset usage already consumed this month. Public prices and billing availability remain unannounced during development.
Personal keys read only the portfolios explicitly selected at issuance, and each request checks current ownership. A project key cannot read portfolios. Publicly sharing a portfolio on the website does not grant an API key permission to access it.
Continue with your first request or personal portfolio access.