Action required: API keys expire on 18 November 2026
Some of the API keys on your ZEN Master account are due to expire at 16:29 UTC on 18 November 2026. Any script, dashboard or integration still using one of those keys will start getting authentication failures from that point, so please create replacement keys before the deadline.
Why this is happening
In November 2025 we introduced a maximum lifetime of one year for ZEN Master API keys. This limits how long a key remains usable if it is ever exposed, and it makes sure keys are reviewed and rotated on a regular basis rather than living indefinitely. Keys that already existed when the change went in were given an expiry date one year out, which is why a number of them land on the same date.
How to check which of your keys are affected
- Log in to ZEN Master as a user with admin rights.
- Go to the API Keys page in your account settings.
- Look at the expiry date for each key. Any key showing 18 November 2026 needs replacing.
How to create a replacement key
- On the API Keys page, choose the option to add a new API key.
- Give it a name that identifies where it is used, for example "automation" or "scheduler". This matters later when you need to work out what a key belongs to.
- Set the permissions to match what the integration actually needs. Choose read only where the integration only reads data, and assign a specific role and tag rather than full admin access wherever you can.
- Set the expiry date. The maximum is one year from the date you create the key.
- Save the key and copy the key value immediately. ZEN Master shows it once and cannot display it again afterwards.
- Update your integration or script with the new key and confirm it works.
- Once the new key is confirmed working, delete the old key.
Points worth noting
- Creating a new key has no effect on the existing one, so you can run both side by side while you cut over and there is no need for an outage.
- An API key authenticates in its own right and is not tied to a user account, so it keeps working after the person who created it has left. Deleting the key is the only way to revoke that access.
- Put a calendar reminder in place ahead of the new expiry date so the next renewal does not come as a surprise.
If you are not sure where a key is being used, or you would like us to confirm which keys are affected on your account, please contact Zixi Support and we will help.