HAPI Key Security

Hey friends! We should have some updates quite soon on our plan to deprecate many of these risks associated with API keys & replace them with a better system. We’re not quite ready to invite folks to try out our new system just yet, but we should have some exciting new things coming in the next few weeks & months to address this. When we do, I’ll post an update on this thread!

@rad Thanks for the update! Really looking forward to what you come up with.

I would love to participate on that :slightly_smiling_face:

Hi All! As @rad mentioned back in June, we’ve been working on a more secure alternative to HAPI Keys. We’re about to launch a small Private Beta. If you’re interested in participating, please complete the form below and someone from the HubSpot Product team will reach out over the next couple of weeks if you meet our beta participant criteria:
Private Beta Form

@MHewett I definitely just signed up for that. Thanks!

I fully support the improvements here @gillytech

Just adding the feature to have a grace period with the previous API key would help us a lot.

This is VERY unfortunate as we may end up with gaps in our integration.

Normally you would have a grace period for the old key which would give you e.g. 24 hours to get all related systems updated. We cannot just release a new version and HOPE that nothing happens during the interval from where the key is changed in HubSpot and then it is deployed with our own app.

@MHewett - just submitted the form.

Hi @CBN You’re 100% correct about the grace period. My initial post was about security, and the grace period is more of an ops thing so not the same subject but absolutely needed. When I go to rotate my key I end up having to open a bunch of terminal windows and prep my commands so I can just paste in the new key and rapidly run through updating each one.

It reduces the error window but obviously this is just silly.

@MHewett I submitted my form the day you announced it but haven’t heard anything. Any updates?

Sorry @gillytech - was a little too fast. The grace period is related, but not 100% security.

I am not sure what happens with the requests through the API in HubSpot, but in our API we check that keys belong to the entity and some other validations before we send it of to do the actual work. I presume something similar happens in HubSpot … I have not tried to enter something invalid here.

Hey @gillytech , I reached out via email on 8/17 and 8/19, but hadn’t heard back. If there’s a better email address to contact you feel free to send me a PM. Thanks!

Great idea. We’re waiting for it!

Hi Everyone, I’m very happy to announce that Private Apps is live! You can learn more here.

Private Apps is live? … AWESOME!!

This is huge news! Thanks HubSpot for hearing us out and delivering better security for everyone. @MHewett It was a pleasure to work with you guys on the beta and I am happy to have contributed :grinning_face:

By the way, there is a new discussion specifically about Private Apps here.