api
API Key Security, Permissions & Best Practices
Essential security practices for managing Nimbica API keys across single and multi-client WordPress installations.
πThis is an interactive step-by-step HowTo guide with 3 verified installation steps.
Security Guidelines for Nimbica API Keys
Your API key grants permission to trigger AI builds, optimize assets, and update edge content. Follow these best practices to keep your account secure:
Best Practices Checklist
- Never Commit Keys to Public Repositories: Do not hardcode API keys into public theme files or GitHub repositories.
- Use Separate Keys Per Client Site: For agencies and multi-site owners, always generate individual site-specific keys rather than sharing master credentials.
- Immediate Key Rotation: If a team member leaves or an environment is decommissioned, regenerate your site key with 1 click from the Nimbica Dashboard.
- Use Email Login for Solo Sites: If you manage your own single site, using email/password login in the plugin is simpler and equally secure β no key management needed.
π Verified Execution Steps (3 Total Steps)
11. Audit Connected Sites
Periodically review your active sites in Nimbica Dashboard β Settings β Connected Sites.
22. Regenerate Key If Compromised
In Site Settings β API Keys, click "Regenerate Key" to revoke the old key and issue a fresh credential.
33. Update WordPress Plugin Setting
Paste the newly generated key into WP-Admin β Nimbica β Settings, or use email login instead.
Was this documentation page helpful?
Last updated on 2026-09-07
