Settings > Developer is where you mint keys for the BrokerPlus public API - only a brokerage admin sees this page at all, because a key is real authority handed to another program.
What an API Key Can Do
A key lets a website lead form, a script or a partner system read and write your book through the API without anyone signing in. It can do everything you can do in BrokerPlus, which is why the card carries a standing warning before you create your first one.
Create a Key
Select New Key, name it after whatever will use it, such as "Website Lead Form", so a future reader knows what it is for, then select Create Key. An organization may hold at most 10 live keys at once - revoke one you no longer need before minting another past that. The new key is pinned to the team you are acting in at the moment you create it, so it keeps reading that team's book no matter which team you switch into afterwards.
Store the Key Safely
The full secret appears exactly once, right after creation - copy it now, because BrokerPlus never shows it again, only its prefix. The calling system sends it as Authorization: Bearer <key>. An API key acts as the broker who created it: it carries that broker's whole authority inside BrokerPlus, with no separate scopes or limits of its own - there is no such thing as a read-only or partial BrokerPlus key. Treat the secret with the same care as that broker's own password, because in practice it is one.
See Which Keys Exist and When They Were Last Used
Every live key is listed with its name, its prefix, who created it, its team, and either "never used" or how long ago it last authenticated a call. The card links out to the API documentation for what a key can actually call.
Revoke a Key
Select Revoke beside a key you no longer need. It stops authenticating immediately. A revoked key is never deleted outright - its name, prefix and creation date stay on the list as a record of what once had access and when that access ended.
What to Do Next
- Export Your Data instead, if you only need a one-time file rather than ongoing access.
- If the other system already speaks to BrokerPlus directly, connect it as an integration rather than handing it a key of its own.