Firm API Keys — Portfolio Data Access

Jessica

Jessica

Last updated on Aug 17, 2026

Pulse Connect isn't just for clients: your firm can create its own API keys that read across every client workspace you manage. Firm keys power firm-side tooling — portfolio dashboards, reporting pipelines, or an AI assistant that answers questions like "which engagements dropped a pillar this quarter?" — without needing a separate key per client.

💡 Tip — Who can use this
Firm administrators, from Settings in the firm portal. Firm keys keep working as long as your firm is active — if the platform team suspends the firm, its keys stop immediately.

Quick reference

Step Action
1 Open Settings and find the API Keys card
2 Create a key with a name and scopes
3 Copy the key — shown only once
4 Revoke keys you no longer use

Step 1: Open Settings and find the API Keys card

In the firm portal, click Settings and scroll to the API Keys card. It lists your firm's keys with their masked prefixes, scopes, status, and last-used time.


Step 2: Create a key with a name and scopes

Click Create API Key, name it for where it will be used (e.g. "Portfolio dashboard"), and choose its scopes. The Read-only preset (Scores, KPIs, Flags, Decisions read, Profile) suits almost all firm reporting. Decisions (write) and Ask Pulse are only needed if your tooling writes decisions or asks Pulse AI questions — note that Ask Pulse usage is metered against each client organization's plan.

Create API key dialog

📝 Note — What a firm key can see
A firm key reads the same data you see in the firm portal across all your client workspaces. Client-facing API keys are narrower — they only see each client's own data, and only periods their advisory analysis has been published for. When in doubt, prefer a read-only firm key.

Step 3: Copy the key — shown only once

The full key is displayed exactly once at creation. Copy it into your password manager or secrets store right away. If it's lost, revoke and re-create — it cannot be retrieved later.

One-time key reveal

❗ Important — Treat firm keys like master credentials
A firm key opens every engagement your firm manages. Store it in a secrets manager (never in code repositories or shared docs), give each integration its own key so you can revoke one without breaking others, and rotate keys when staff with access leave.

Step 4: Revoke keys you no longer use

Each key row has a Revoke button — it takes effect on the next request, and the row stays listed as REVOKED for your records. Do this when a tool is decommissioned or a key may have been exposed.