πŸ€–NEW:AI-Powered Incremental Builds β€” your site updates in under 30 seconds. See what's new β†’
api

API Key Security, Permissions & Best Practices

Essential security practices for managing Nimbica API keys across single and multi-client WordPress installations.

πŸ“‹This is an interactive step-by-step HowTo guide with 3 verified installation steps.

Security Guidelines for Nimbica API Keys

Your API key grants permission to trigger AI builds, optimize assets, and update edge content. Follow these best practices to keep your account secure:

Best Practices Checklist

  • Never Commit Keys to Public Repositories: Do not hardcode API keys into public theme files or GitHub repositories.
  • Use Separate Keys Per Client Site: For agencies and multi-site owners, always generate individual site-specific keys rather than sharing master credentials.
  • Immediate Key Rotation: If a team member leaves or an environment is decommissioned, regenerate your site key with 1 click from the Nimbica Dashboard.
  • Use Email Login for Solo Sites: If you manage your own single site, using email/password login in the plugin is simpler and equally secure β€” no key management needed.

πŸ“‹ Verified Execution Steps (3 Total Steps)

11. Audit Connected Sites

Periodically review your active sites in Nimbica Dashboard βž” Settings βž” Connected Sites.

22. Regenerate Key If Compromised

In Site Settings βž” API Keys, click "Regenerate Key" to revoke the old key and issue a fresh credential.

33. Update WordPress Plugin Setting

Paste the newly generated key into WP-Admin βž” Nimbica βž” Settings, or use email login instead.

Was this documentation page helpful?
Last updated on 2026-09-07