One of our internal apps suddenly stopped working, and it looks like the Hexnode API key it was using may have changed. Is there a way to check who generated a new API key or revoked the old one?
One of our internal apps suddenly stopped working, and it looks like the Hexnode API key it was using may have changed. Is there a way to check who generated a new API key or revoked the old one?
Yes. You can verify API key-related changes from the Audit History in the Hexnode UEM portal.
Go to Reports > Built-in Reports > Audit > Integration events > Hexnode API. Look for audit events such as:
These entries include the technician associated with the action, so you can identify who generated or revoked the API key.
If the API key was reset, integrations or applications using the previous key will stop authenticating until they are updated with the current API key. Accidental use of the Reset option can therefore cause connected systems to fail if the stored key is not updated afterward.
Regards,
Simon Scott
Hexnode UEM
Could pressing Reset have created the new key even if the technician didn’t think of it as “generating” one?
Yes. Using Reset regenerates the API key. From an audit and integration perspective, that effectively creates a new key and invalidates the old one.
To prevent accidental disruption, it is a good idea to review technician permissions and limit access to the Admin tab only to users who need it, as that is where the API key is managed. Any external application using the API should also be updated immediately after a reset with the newly generated key.
Don't have an account? Sign up