# API - Security Initiatives

> TABLE OF CONTENTS Auto-deletion of API keys after 90 days of inactivity Auto-deletion of API keys after 90 days of inactivity Agency or sub-account API…

- Source: https://docs.ghlcustomercare.com/docs/developer-resources/developer-resources-2/api-security-initiatives
- Section: Developer Resources / Developer Resources
- Reading time: 1 min
- Images: 2, each explained below
- Modified on Wed, 24 Jun at 10:35 PM

---
**TABLE OF CONTENTS**

-   [Auto-deletion of API keys after 90 days of inactivity](#auto-deletion-of-api-keys-after-90-days-of-inactivity)

### **Auto-deletion of API keys after 90 days of inactivity**

-   Agency or sub-account API keys that have not been used in the past 90 days will be automatically deleted.
-   **Deletion cadence**: This activity will be once a quarter (automated) across all agency and sub-account API keys.
-   **Customer communication**:
    -   The impacted Agency and Sub-accounts admins will receive three in-app notifications giving them a heads-up - 15 days, 7 days, and 1 day before the deletion
    -   Agency admins (included those whose locations are impacted) will receive an email 15 days prior with a complete summary of the upcoming deletion
    -   One day before the deletion, for 24 hours, the impacted agencies and sub-accounts will see a banner informing them about the upcoming deletion.

---

## **Inactive Legacy API Keys Expire After 90 Days**

Inactive legacy API keys are now marked as **Expired** after 90 days of inactivity to reduce unnecessary credential exposure and improve account security.

This applies to both:

-   Agency-level legacy API keys
-   Location-level legacy API keys

**Important:**

Active keys are not affected

Expired keys remain visible in settings

If access is still needed, an expired key can be used again after it is **rotated** or **refreshed**

New **v1 API key creation** is no longer supported

**Private Integration Tokens (PIT)** are the recommended option for any new credentials

Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity.

![Inactive Legacy API Keys Expire After 90 Days (image 1 of 2)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155074448883/original/RhQDyvp9LPwxnWGiTRCJJ06kgTW4RZ9u8w.png)

**Inactive Legacy API Keys Expire After 90 Days (image 1 of 2)**

This screenshot appears in the "Inactive Legacy API Keys Expire After 90 Days" section of "API - Security Initiatives". The text alongside this image reads: Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity. This part of the guide covers 2 fields, listed below.
- What this covers: Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity.
- Fields: Agency-level legacy API keys, Location-level legacy API keys
- Controls: Expired, rotated, refreshed, v1 API key creation, Private Integration Tokens (PIT)

Full procedure:

1. Agency-level legacy API keys
2. Location-level legacy API keys

![Inactive Legacy API Keys Expire After 90 Days (image 2 of 2)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155074448869/original/f1bCOnVwSGmcNjFwQGC7orrvfKpkLxvSCQ.png)

**Inactive Legacy API Keys Expire After 90 Days (image 2 of 2)**

This screenshot appears in the "Inactive Legacy API Keys Expire After 90 Days" section of "API - Security Initiatives". The text alongside this image reads: Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity. This part of the guide covers 2 fields, listed below.
- What this covers: Users may also receive email notifications when a legacy API key is approaching expiration due to inactivity.
- Fields: Agency-level legacy API keys, Location-level legacy API keys
- Controls: Expired, rotated, refreshed, v1 API key creation, Private Integration Tokens (PIT)

Full procedure:

1. Agency-level legacy API keys
2. Location-level legacy API keys

---

Documentation for GHL Customer Care. Support: support@ghlcustomercare.com