Skip to main content

Manage service users and API credentials

An API key has the permissions and scope of the standard user or service user that owns it. For each integration:

  1. Create a dedicated service user.

  2. Assign only the required Account Manager and product roles.

  3. Generate only the credentials the integration requires.

  4. Store credentials in an approved secrets-management system.

  5. Monitor expiration dates and replace credentials before they expire.

  6. Revoke credentials immediately if they may have been exposed.

  7. Disable or delete credentials when the integration is retired.

DigiCert limits new cryptographic configurations to the algorithms and key strengths available in the FedRAMP deployment.