# Difference between API Keys and Personal Access Token

**URL:** <https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756>\
**Category:** SHF Discussion and Questions\
**Tags:** apis, identity-security-cloud\
**Created:** [October 25, 2023, 1:30pm UTC](https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756 "2023-10-25T13:30:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![khalilgahbiche](https://avatars.discourse-cdn.com/v4/letter/k/6de8d8/32.png) [@khalilgahbiche](https://developer.sailpoint.com/discuss/u/khalilgahbiche)\
**Post date:** [October 25, 2023, 1:30pm UTC](https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756/1 "2023-10-25T13:30:28Z")

</div>

Dear all,  
If you ever have to use Client ID and Secret in a script, what whould you choose, API keys or Personal Access Token?  
For my part, I’ve read [this article](https://documentation.sailpoint.com/saas/help/common/api_keys.html) and still can’t answer the question. But, so far, I see one caveat for the Personal Access Token, is that we need to create a service account for it, meanwhile, no need for a specific user to manager API keys.  
Please correct me if I’m wrong.  
Thanks.

---

<div class="post-metadata">

**Author:** ![edmarks](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/edmarks/32/2896_2.png) [@edmarks](https://developer.sailpoint.com/discuss/u/edmarks)\
**Post date:** [October 25, 2023, 1:35pm UTC](https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756/2 "2023-10-25T13:35:48Z")

</div>

This is a bit of a gray area from my perspective because I believe there are certain API calls (I don’t have any specific examples at the moment) that require a user context which is only in the PAT. There’s a LONG history to API keys / PATs that’s been a winding road over the years, so we generally still default to a service user with PAT vs. using the API key.

---

<div class="post-metadata">

**Author:** ![khalilgahbiche](https://avatars.discourse-cdn.com/v4/letter/k/6de8d8/32.png) [@khalilgahbiche](https://developer.sailpoint.com/discuss/u/khalilgahbiche)\
**Post date:** [October 25, 2023, 1:52pm UTC](https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756/3 "2023-10-25T13:52:46Z")

</div>

Alright, thanks @edmarks , I’ll use PATs with a service account, but as soon as someones confirms that API keys are pretty the same thing, I’ll switch. I’m still interested btw to know what differences there are between them, if anyone has any reference, please share 😉

---

<div class="post-metadata">

**Author:** ![edmarks](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/edmarks/32/2896_2.png) [@edmarks](https://developer.sailpoint.com/discuss/u/edmarks)\
**Post date:** [October 25, 2023, 2:03pm UTC](https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756/4 "2023-10-25T14:03:09Z")

</div>

{{baseUrl}}/workflows is an example of a BETA API call that appears to fail with the API key but is successful with the PAT.

I was looking at the documentation for the V3 API’s and they specifically note “API” and “ORG\_ADMIN” in many of these. I found a couple that only listed “ORG\_ADMIN” but they appeared to work with the API KEY also, so the confusion lingers.

---

<div class="post-metadata">

**Author:** ![anujoseIC](https://avatars.discourse-cdn.com/v4/letter/a/c5a1d2/32.png) [@anujoseIC](https://developer.sailpoint.com/discuss/u/anujoseIC)\
**Post date:** [October 26, 2023, 10:44am UTC](https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756/5 "2023-10-26T10:44:08Z")

</div>

From my understanding, the API token with client credential grant type does not have a user linked to it. This type of token will not be able to call all the IDN REST endpoints. For example, the role revocation API end point /v3/access-requests will give a forbidden error while using the client credential as this end point excepts the call only from a valid user which makes sense from a audit and security standpoint.

The PAT token on the other hand is also of client credential grant type but associated to a user. The PAT associates the user that created the PAT to the generated access tokens, giving those tokens the same user level as the user that created it. So if you are an Admin user and you generate a PAT with `sp:scopes:all` , your PAT can access **almost** every API endpoint.

While observing the response of the authentication call using a PAT and client credential token you can observe the difference, while PAT authentication response provides identity id and user name info, client credential token does not provide this.

---

<div class="post-metadata">

**Author:** ![khalilgahbiche](https://avatars.discourse-cdn.com/v4/letter/k/6de8d8/32.png) [@khalilgahbiche](https://developer.sailpoint.com/discuss/u/khalilgahbiche)\
**Post date:** [October 26, 2023, 1:13pm UTC](https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756/6 "2023-10-26T13:13:14Z")

</div>

@anujoseIC , that’s clear, thanks for the reply.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [December 25, 2023, 1:13pm UTC](https://developer.sailpoint.com/discuss/t/difference-between-api-keys-and-personal-access-token/19756/7 "2023-12-25T13:13:43Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
