Managing API Keys and OAuth 2.0 Tokens
This section describes to how an API Provider (owner) can manage API keys and OAuth2 tokens.
To manage the various operations (Generate, Renew, Revoke or Delete) on an API key or OAuth token, you must belong to a role that has the Modify Assets permission for the organization in which the API resides. Else, at least have the Full instance-level permission on the API itself. However, if you belong to a role that has the Manage Assets permission, you can configure the consumption settings for APIs in all organizations. To see a list of the predefined roles that include the Manage Assets or Modify Assets permission, see the CentraSite Administrator’s Guide .