# API key for all environments?

**URL:** https://forums.suse.com/t/api-key-for-all-environments/279
**Category:** Rancher 1.x
**Created:** [August 20, 2015, 1:01pm UTC](https://forums.suse.com/t/api-key-for-all-environments/279 "2015-08-20T13:01:28Z")
**Posts on this page:** 10
**Page:** 1

<div class="post-metadata">

### Author: ![tobowers](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/tobowers/32/22_2.png) [@tobowers](https://forums.suse.com/u/tobowers)
#### Post date: [August 20, 2015, 1:01pm UTC](https://forums.suse.com/t/api-key-for-all-environments/279/1 "2015-08-20T13:01:28Z")

</div>

Is it possible to create an API key that has access to all the environments?

We are creating an app that updates external DNS entries based on rancher load balancers. Our current plan was to provide key per environment and then have the app cycle through it.

---

<div class="post-metadata">

### Author: ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)
#### Post date: [August 20, 2015, 1:32pm UTC](https://forums.suse.com/t/api-key-for-all-environments/279/2 "2015-08-20T13:32:49Z")

</div>

It is not exposed through the UI, but yes:

Go to the User menu -\> API & Keys, click the endpoint. That brings up the API, authenticating with a token as your user (with access to all environments too). Navigate up to `/v1/apikeys`, click Create. Make sure the type says `apiKey`, add a name and such if you want, and show/send request. Copy the public and secret values.

That API key will have access to anything your user does. The URL structure will be a little different, you can list the environments at `/v1/projects` and all the stuff you normally see at e.g. `/v1/containers` is now underneath there at `/v1/projects/:id/containers` (technically this URL works with a normal key too, there is just always only one project/environment to see instead of many).

If you haven’t run into this yet, UI “environment” == API “project” and UI “stack” == API “environment”. We will eventually do a round of cleanup on the API and make it match the UI terms, after they’ve had long enough to stick that we’re confident they won’t change again 😄

---

<div class="post-metadata">

### Author: ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)
#### Post date: [August 20, 2015, 1:46pm UTC](https://forums.suse.com/t/api-key-for-all-environments/279/3 "2015-08-20T13:46:12Z")

</div>

I don’t think the `/v1/subscribe?eventNames=resource.change` WebSocket works with this kind of key to give you change events for all the projects/environments. You can try it but may end up having to poll for changes to balancers, or open a WebSocket per-project by adding `&projectId=`.

---

<div class="post-metadata">

### Author: ![tobowers](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/tobowers/32/22_2.png) [@tobowers](https://forums.suse.com/u/tobowers)
#### Post date: [August 20, 2015, 1:46pm UTC](https://forums.suse.com/t/api-key-for-all-environments/279/4 "2015-08-20T13:46:36Z")

</div>

Thanks! I’ll give this a shot. We are currently planning on polling :).

---

<div class="post-metadata">

### Author: ![Rucknar](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/rucknar/32/107_2.png) [@Rucknar](https://forums.suse.com/u/Rucknar)
#### Post date: [March 8, 2016, 3:21pm UTC](https://forums.suse.com/t/api-key-for-all-environments/279/5 "2016-03-08T15:21:07Z")

</div>

Just been pointed towards this post, might be quite useful for our implementation.  
Quick question, is this global API key supported by the rancher labels that can be used within compose files?

---

<div class="post-metadata">

### Author: ![denise](https://avatars.discourse-cdn.com/v4/letter/d/82dd89/32.png) [@denise](https://forums.suse.com/u/denise)
#### Post date: [March 9, 2016, 6:38am UTC](https://forums.suse.com/t/api-key-for-all-environments/279/6 "2016-03-09T06:38:13Z")

</div>

What do you mean by “supported by rancher labels”?

---

<div class="post-metadata">

### Author: ![Rucknar](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/rucknar/32/107_2.png) [@Rucknar](https://forums.suse.com/u/Rucknar)
#### Post date: [March 10, 2016, 1:39am UTC](https://forums.suse.com/t/api-key-for-all-environments/279/7 "2016-03-10T01:39:12Z")

</div>

Apolgoies, should of listed it. I meant using the label `io.rancher.container.agent.role` Currently i use the `environment` value, is there one for the global key?

---

<div class="post-metadata">

### Author: ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)
#### Post date: [March 10, 2016, 4:45pm UTC](https://forums.suse.com/t/api-key-for-all-environments/279/8 "2016-03-10T16:45:46Z")

</div>

There is not an equivalent that gives access to all environments… There would be a variety of security issues with that.

---

<div class="post-metadata">

### Author: ![chenjun3092](https://avatars.discourse-cdn.com/v4/letter/c/e56c9b/32.png) [@chenjun3092](https://forums.suse.com/u/chenjun3092)
#### Post date: [June 17, 2016, 2:09am UTC](https://forums.suse.com/t/api-key-for-all-environments/279/9 "2016-06-17T02:09:59Z")

</div>

I tried to follow vincent’s answer to create a apikey for all environments.

 ![](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/a/a72c346bca7eabcac7b041afbb4d6946b5853846.png)

Which accountId I should choose for all environments? I created apikeys of “admin” and “systemadmin” accountId without inputing publicValue and secretValue, then ran go-rancher client with these apikeys to list environments’ info, But it didn’t show anything or just refused by rancher for “Unauthorized”.

---

<div class="post-metadata">

### Author: ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)
#### Post date: [June 17, 2016, 6:26pm UTC](https://forums.suse.com/t/api-key-for-all-environments/279/10 "2016-06-17T18:26:26Z")

</div>

The thing called an “Environment” in the UI is called a `project` in the API, and the thing called a “Stack” in the UI is called an `environment` in the API. So you want to list `project`s with the account key, not `environment`s.

The API key will have access to whatever projects the account has access to. You probably want admin (1a1) if you have access control off or are the one that turned it on. But creating account API keys is in the UI now as of 1.0 or so, so you can just do it there instead. In the API screen, expand the “Advanced Options” toggle.
