Unexpected Hexnode API key generated email sent to adminsSolved

Participant
Discussion
3 days ago Oct 09, 2026

We received an email saying an API key was generated in our Hexnode portal, but none of our admins intentionally created or enabled an API key. The notification went to the administrators, so it raised some security concerns.

Is this email always caused by someone manually generating a key? Also, if the portal/subscription is no longer active, does that API key still pose any risk?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
3 days ago Oct 09, 2026
Marked SolutionPending Review

Hi @shirleyc ,

An API key generation email is automatically sent to the administrators of a Hexnode UEM portal whenever an API key is generated or enabled for that portal.

A few points to clarify the behavior:

  • Hexnode UEM portals can have an API key generated by default for API-based endpoint management.
  • If an existing API key is revoked and then re-enabled, a new API key is generated.
  • This new key generation triggers an email notification to all administrators listed in the portal.
  • The notification does not necessarily mean that an unauthorized person generated the key.

If the portal or subscription has been cancelled, the API key is disabled and cannot be used to access or manage devices through the portal.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
2 days ago Oct 09, 2026
Marked SolutionPending Review

So if none of our admins clicked anything, it could still happen because the existing key was revoked and enabled again? That was the confusing part for us.

Marked SolutionPending Review
Hexnode Expert
2 days ago Oct 09, 2026
Marked SolutionPending Review

Yes. If the existing API key is revoked and then enabled again, Hexnode UEM generates a fresh key instead of restoring the old one. That action triggers the same administrator notification.

For security-sensitive cases, administrators can review portal activity and technician access to confirm who performed the revoke or enable action. If the portal is already inactive or cancelled, the generated key is disabled along with the portal, so it will not provide active API access.

Regards,
Isabel Lora
Hexnode UEM

Save