Permissions
Every CertHub API key inherits the permissions of the user who created it. The API does not bypass the CertHub permission model.
What that means in practice
- If the user can read a product or knowledge topic in the dashboard, the key can usually read it via the API
- If the user cannot access an object in the UI, the key cannot access it via the API either
- If you regenerate the key, every integration using the old key stops working immediately
Typical failure mode
If a request returns 403 Forbidden, the key is valid but the user behind it does not have permission for that operation.
Check:
- Which user created the key
- Whether that user can perform the same action in CertHub
- Whether the user's assigned roles include the right read, create, edit, approve, download, or delete permissions
For more on the role model, see Application Settings & User Management and Permissions Overview.
Authentication reminder
Authentication and authorization are separate:
- 401 usually means the key is missing, invalid, or expired
- 403 usually means the key is valid, but the user does not have access