API gateway
What is an API key and what is it for
An API key is used to securely connect external tools, agencies, or your own systems to Heureka services – it works much like a password that your integration uses on your behalf.
An API key currently provides two types of access:
- Conversion Tracking – download data about orders that came to you from Heureka.
- Offer Updating – send changes to your offers directly to Heureka, without waiting for the XML feed to be downloaded.
A new key automatically receives both types of access.
Where to find API keys
In the administration, go to Settings → API Keys in the left menu.
If you don’t have a key yet, the page shows the empty state “You don’t have any API keys yet” with a Create API Key button and a View Documentation link.
How to create a new API key
- In the Settings → API Keys section, click the Create API Key button.
- The Create API Key panel opens. In the Key Name field, enter a descriptive name that will help you recognize the key later (e.g. “PPC Agency” or “Internal Reporting”).
- In the Access section, check what the key will be used for – Conversion Tracking and Offer Updating. At this time, the key receives both types of access automatically.
- Click the Create API Key button (bottom right).
- Save the created key securely right away – for security reasons, it is displayed in full only once, and the same key cannot be generated again later.
List of created API keys
In the API Key List section, you can see the following for each key:
- The key name and its masked form (only the last few characters are shown, e.g. ••••loQktlNA==),
- The access the key has,
- The date the key was created,
- Whether the key is Active,
- The option to Invalidate the key.
Next to the key list, you will also find the Open API Documentation link – technical details, endpoints, and usage examples.
How to invalidate a key
If you no longer use a key, or suspect it has been misused, you can invalidate it at any time:
- In the API key list, click the Invalidate link next to the relevant key.
- The Invalidate API Key confirmation window appears, warning you that the key will stop working immediately and that integrations using it will no longer be able to retrieve data or work with Heureka services.
Multiple keys for one account
You can create several keys at once – for example, one for yourself and a separate one for the agency that manages your campaigns. Each key can be named, monitored, and invalidated independently, without affecting your other integrations.
Security recommendations
- Never share your API key publicly (e.g. in code on GitHub, in public forums, etc.).
- Create a separate key for each integration (agency, custom system) – this makes it easier to invalidate a key without affecting your other integrations.
- Save the key in a password manager right after creating it – Heureka will not display it in full again.
- Regularly review and invalidate unused keys.