# Creating Api Keys

**URL:** <https://forum.serverless.com/t/creating-api-keys/847>\
**Category:** Serverless Framework\
**Created:** [November 28, 2016, 2:19pm UTC](https://forum.serverless.com/t/creating-api-keys/847 "2016-11-28T14:19:42Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![shawnmullen](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@shawnmullen](https://forum.serverless.com/u/shawnmullen)\
**Post date:** [November 28, 2016, 2:19pm UTC](https://forum.serverless.com/t/creating-api-keys/847/1 "2016-11-28T14:19:42Z")

</div>

I followed the documentation on creating api keys for my api. After sls deploy, I see that the key was created in api gateway, however it is not associated with any particular api. All the endpoints I marked as private in serverless.yml did have their “API key Required” flag set to true, and the key itself was created, but it is not associated with the api. Is there another property I need to set in serverless.yml? Or, do I need to “hook up” the api key manually?

---

<div class="post-metadata">

**Author:** ![shawnmullen](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@shawnmullen](https://forum.serverless.com/u/shawnmullen)\
**Post date:** [November 29, 2016, 3:03am UTC](https://forum.serverless.com/t/creating-api-keys/847/2 "2016-11-29T03:03:40Z")

</div>

Has someone verified that this is a problem, or am I simply doing something wrong. Any info would be appreciated.

---

<div class="post-metadata">

**Author:** ![rwinbush](https://avatars.discourse-cdn.com/v4/letter/r/82dd89/32.png) [@rwinbush](https://forum.serverless.com/u/rwinbush)\
**Post date:** [December 9, 2016, 1:58am UTC](https://forum.serverless.com/t/creating-api-keys/847/3 "2016-12-09T01:58:53Z")

</div>

I’m having the same problem.

---

<div class="post-metadata">

**Author:** ![DavidWells](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/davidwells/32/201_2.png) [@DavidWells](https://forum.serverless.com/u/DavidWells)\
**Post date:** [December 9, 2016, 1:59am UTC](https://forum.serverless.com/t/creating-api-keys/847/4 "2016-12-09T01:59:50Z")

</div>

Can you post the `serverless.yml` files you are using?

---

<div class="post-metadata">

**Author:** ![shawnmullen](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@shawnmullen](https://forum.serverless.com/u/shawnmullen)\
**Post date:** [December 9, 2016, 3:24am UTC](https://forum.serverless.com/t/creating-api-keys/847/5 "2016-12-09T03:24:28Z")

</div>

I simply added apiKeys property to the serverless.yml file and set the private attribute to true for all the api methods that needed it.

I also tried adding UsagePlan to resources and was able to create a UsagePlan but couldn’t connect the key to the plan.

---

<div class="post-metadata">

**Author:** ![shawnmullen](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@shawnmullen](https://forum.serverless.com/u/shawnmullen)\
**Post date:** [March 30, 2017, 3:25pm UTC](https://forum.serverless.com/t/creating-api-keys/847/6 "2017-03-30T15:25:01Z")

</div>

This is still an issue.

The serverless documentation says that as a result of a CloudFormation limitation, I have to manually connect my api keys to a usage plan. However, according to the CloudFormation documentation, it seems pretty trivial to connect the two. Is this problem really a CloudFormation limitation? If its not, can we get this fixed sooner rather than later? One of my main goals is to be able to create an api without performing manual steps.

---

<div class="post-metadata">

**Author:** ![rowanu](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/rowanu/32/75_2.png) [@rowanu](https://forum.serverless.com/u/rowanu)\
**Post date:** [March 30, 2017, 9:39pm UTC](https://forum.serverless.com/t/creating-api-keys/847/7 "2017-03-30T21:39:33Z")

</div>

Can you share your `serverless.yml` (at least just the relevant snippet) as @DavidWells mentioned above?

---

<div class="post-metadata">

**Author:** ![shawnmullen](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@shawnmullen](https://forum.serverless.com/u/shawnmullen)\
**Post date:** [March 31, 2017, 3:47am UTC](https://forum.serverless.com/t/creating-api-keys/847/8 "2017-03-31T03:47:57Z")

</div>

i already removed everything that I was using to try to do it using serverless. Severless documentation already states that it is not possible to connect an api key to a usage plan. The only thing I am doing now is using serverless to create the usage plan, and the api key. I then connect the two together using the aws console:

```
UserDbUsagePlan:
  Type: AWS::ApiGateway::UsagePlan
  DependsOn: ApiGatewayRestApi
  Properties:
    Description: My Usage plan.
    UsagePlanName: my-usage-plan

```

What I was trying to do is using the resources section of the serverless.yml file and create the resources according to aws documentation:

[http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-apigateway-apikey.html](http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-apigateway-apikey.html)

[http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-apigateway-usageplankey.html](http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-apigateway-usageplankey.html)

[http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-apigateway-usageplan.html](http://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-resource-apigateway-usageplan.html)

I tried several different approaches, but it seemed to come down to the fact I couldn’t get the proper stageId nor could I get a reference to the keyId of the newly created apiKey.

---

<div class="post-metadata">

**Author:** ![rowanu](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/rowanu/32/75_2.png) [@rowanu](https://forum.serverless.com/u/rowanu)\
**Post date:** [March 31, 2017, 4:08am UTC](https://forum.serverless.com/t/creating-api-keys/847/9 "2017-03-31T04:08:46Z")

</div>

I haven’t used API Keys personally, so just coming at it from a CFN angle here.

You should be able to `Ref` the automatically generated [logical ID](https://serverless.com/framework/docs/providers/aws/guide/resources#aws-cloudformation-resource-reference) (i.e. the API Key, which looks like `ApiGatewayApiKey{SequentialID}`) to use it in your `UsagePlan` in the `resources` section of your `serverless.yml`, no?

---

<div class="post-metadata">

**Author:** ![shawnmullen](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@shawnmullen](https://forum.serverless.com/u/shawnmullen)\
**Post date:** [March 31, 2017, 9:13am UTC](https://forum.serverless.com/t/creating-api-keys/847/10 "2017-03-31T09:13:01Z")

</div>

Well, it is working now.

1. Thanks for pointing out the APiGatewayApiKey{SequentialID}. I guess I didn’t really understand the serverless documentation regarding the logical Id naming conventions until you pointed this out.

2. AWS’s documentation regarding AWS::ApiGateway::UsagePlan, can’t be followed exactly according to the YAML example. They use a Ref: StageName. Can’t use Ref. If you do, serverless fails to create the script. I think if the serverless documentation didn’t say that connecting the keys to the plans wasn’t possible, I wouldn’t have given up so easily when I hit this error the first time.

3. Below is what I ended up with:

provider:  
name: aws  
runtime: nodejs4.3  
stage: dev  
apiKeys:  
- MyApiKey

resources:  
Resources:  
ApiGatewayRestApi:  
Type: AWS::ApiGateway::RestApi  
Properties:  
Name: my-service-api

```
MyUsagePlan:
  Type: AWS::ApiGateway::UsagePlan
  DependsOn: ApiGatewayApiKey1
  Properties:
    UsagePlanName: my-usage-plan
    ApiStages:
      - ApiId:
          Ref: ApiGatewayRestApi
        Stage: ${self:provider.stage}

MyUsagePlanKey:
  Type: AWS::ApiGateway::UsagePlanKey
  DependsOn: MyUsagePlan
  Properties :
    KeyId:
      Ref: ApiGatewayApiKey1
    KeyType: API_KEY
    UsagePlanId:
      Ref: MyUsagePlan

```

Making MyUsagePlan dependent upon ApiGatewayApiKey1 was also key. Without it, the attempt to create the plan always happened too soon and cloudformation would fail (API Stage not found). Again, if the serverless documentation didn’t state that connecting the key to the plan wasn’t supported, I wouldn’t have given up so soon when I hit this error the first time.

---

<div class="post-metadata">

**Author:** ![mitchellLisa](https://avatars.discourse-cdn.com/v4/letter/m/7993a0/32.png) [@mitchellLisa](https://forum.serverless.com/u/mitchellLisa)\
**Post date:** [September 11, 2017, 10:29pm UTC](https://forum.serverless.com/t/creating-api-keys/847/11 "2017-09-11T22:29:37Z")

</div>

Thank you for sharing Shawn! However, it isn’t clear to me whether you are also using the serverless.yml file to create the API Keys or does this assume that they already exist?

Can you share a complete file so that we can also see how you are referring to the keys (in the provider section and/or in the functions section)?

So close!!!

---

<div class="post-metadata">

**Author:** ![shawnmullen](https://avatars.discourse-cdn.com/v4/letter/s/ecb155/32.png) [@shawnmullen](https://forum.serverless.com/u/shawnmullen)\
**Post date:** [September 12, 2017, 6:34am UTC](https://forum.serverless.com/t/creating-api-keys/847/12 "2017-09-12T06:34:37Z")

</div>

The example i shared is from my severless.yml file.

However, this is an old post and my solution is no longer needed. The current version of serverless handles everything automatically.

---

<div class="post-metadata">

**Author:** ![mateen-hussain](https://yyz2.discourse-cdn.com/flex036/user_avatar/forum.serverless.com/mateen-hussain/32/3567_2.png) [@mateen-hussain](https://forum.serverless.com/u/mateen-hussain)\
**Post date:** [October 11, 2018, 1:08pm UTC](https://forum.serverless.com/t/creating-api-keys/847/13 "2018-10-11T13:08:33Z")

</div>

can you please share how to reuse existing apikey with latest version?
