Stripe read-only key builder.
When an analytics tool, a dashboard, or your bookkeeper asks for Stripe access, give it a restricted key that can only read what it needs, never your secret key. Pick what the tool needs to see and get the exact permissions to set to Read. Everything else stays at None.
How to use it
- Pick what the tool needs
Tick what it has to see, or start from a preset. The list shows exactly which permissions to set to Read.
- Create the key in Stripe
Name it for the tool, set the listed permissions to Read, and leave everything else at None.
Developers›API keys›Create restricted key - Check it and hand it over
It should start with rk_live_. Type the first characters below to check, then give the tool that key only.
Is this the right kind of key?
Type just the first few characters. You never need to paste a whole key here, and nothing you type leaves your browser.
Start typing the key's first characters.
Why a restricted key, not your secret key
- A secret key can do anythingRefund payments, cancel subscriptions, change payout details, read every customer. If a tool you gave it to is breached, so is your Stripe account.
- A restricted key does only what you choseSet to Read, it can look but not change. A leak shows numbers, it cannot move money.
- One key per toolName each key for the tool using it. When you stop using the tool, revoke that one key and nothing else breaks.
- Read only what it needsA revenue dashboard does not need disputes or payouts. Fewer permissions means less exposed if anything goes wrong.
Stripe's own guide to restricted keys is at docs.stripe.com/keys/restricted-api-keys. The permission names in the builder are the ones the Dashboard shows, from Stripe's permissions reference, checked October 2026.
Restricted key questions
Something else? Email us.
How do I make a read-only Stripe API key?
Create a restricted key in the Stripe Dashboard under Developers, API keys. Set the resources the tool needs to Read and leave everything else at None. The builder above lists which ones to set.
What is the difference between rk_live and sk_live?
Keys starting sk_live_ are secret keys with full access to your account. Keys starting rk_live_ are restricted keys that can only do what you allowed when you created them. Share restricted keys with tools; keep secret keys to your own servers.
Which permissions does a revenue or MRR dashboard need?
Usually Subscriptions, Customers, Charges and Refunds, and Invoices, all at Read. Some tools also read Prices and Products to name plans. Check the tool's own setup guide too, and start from the Revenue preset above.
Can I change a restricted key's permissions later?
Yes. Edit the key in the Dashboard and change any permission. The key itself stays the same, so the tool keeps working with the new access.
Does a restricted key work in test mode?
Yes. Create it while viewing test data and it starts with rk_test_. Test and live keys are separate, so make one of each if a tool needs both.
Is anything I choose here saved or sent?
No. The builder and the key check run in your browser. Never paste a full secret key into any website, this one included.
Is it safe to give a restricted key to a third-party app?
Much safer than a secret key. A read-only restricted key cannot move money or change your account, and you can revoke it on its own at any time. Give each app its own key so you can see and cut off each one separately.
How do I revoke a Stripe API key?
In the Dashboard, open Developers, then API keys, open the menu next to the key, and delete it. The tool using it stops reaching Stripe right away; nothing else is affected.
What happens if a tool's key is missing a permission?
Stripe refuses that request with a permissions error, and the tool usually shows the data as missing. Edit the key, set the missing resource to Read, and the same key works without changing it in the tool.