How do I create API Credentials in Nightjar?
3 min read
Create a Nightjar API Credential in Settings → API → New credential. You must be the Team owner and have an active paid Subscription. Choose its permissions and expiry, then copy the key before closing the dialog: Nightjar shows the secret only once.
A Nightjar API Credential connects your server integration to one Team's Products, Library and Credits without sharing a personal login. Your scripts can work with the same resources your Team uses in Nightjar, so programmatic image production can continue from your existing product and photographic direction.
Create the credential
- Open the Account menu, the circular button with your initial. If you belong to multiple Teams, select the Team your integration should use.
- Choose Settings, then API.
- Select New credential.
- Enter a Name that identifies its purpose, such as “Production integration” or “Reporting”. Names can contain up to 80 characters.
- Choose Permissions: Read only for retrieving resources, or Full access for an integration that also creates, updates or deletes supported resources and starts Generations. Choose only the access your integration needs; the form defaults to Full access.
- Choose an Expiry: Never, 30 days, 60 days, 90 days or 1 year. The default is Never.
- Select Create credential. In Copy your API key, select Copy key and save the secret securely before selecting Done.
API Access is included with every paid plan. If the API tab says only the Team owner can manage credentials, ask that owner to create one. If it shows Upgrade, the selected Team does not currently have the Subscription access needed to create credentials.
Store the key and verify the connection
Store the key in a secret manager and make it available to your server through its secure configuration, such as an environment variable. Keep it out of browser code, source control and logs. A Read only key is still a secret because it grants access to Team resources.
Follow the Nightjar API quickstart to send a server-side GET https://api.nightjar.so/v1/team request with the key in the Authorization: Bearer header. This retrieves your Team without starting a Generation. Check the returned Team, credential name and permission profile before connecting it to production work. The response also reports remaining Credits and effective API capabilities.
Once the secret dialog is closed, the credential list shows identifying information such as its prefix, permissions, expiry and last-used date, not the full key. If you did not save the key, rotate the credential or create a replacement.
Rotate or revoke a credential
To replace an active key, select Rotate beside its credential in Settings → API. Copy the new key and update your integration. Both keys remain valid during the overlap, so verify that the integration works with the new key before revoking the old one. Use the displayed prefix to distinguish the two entries.
Rotation keeps the original name, permissions and expiry date. It does not extend the lifetime or automatically revoke the old key after a fixed grace period. The old key remains usable until it expires or you revoke it. To choose different permissions or a later expiry, create a new credential instead.
To end access, select Revoke beside the old credential, then confirm Revoke credential. Subsequent requests using that key fail immediately, and revocation cannot be undone. If a key has been exposed, revoke it promptly and replace it in your integration.
What happens if the Subscription lapses?
Existing, unexpired and unrevoked credentials can still read Team resources after the Subscription lapses. Creative writes require both Full access and an active Subscription; creating or rotating credentials also requires an active Subscription. A successful read therefore does not prove that the integration can generate images.
The current API settings screen shows Upgrade instead of the credential list when the Team loses Subscription access. If you need help revoking an existing key in that state, use Contact Us in the Account menu. Never send the API key to support; for a failed request, share its Request-Id, endpoint and approximate time.
Consistent and on brand AI photoshoots, optimized for conversion.
Nightjar