Hi there,
We're excited to announce OneSignal's new and improved API authentication keys to enhance the security of your applications.
This update helps ensure that only trusted sources can interact with your OneSignal apps via our API. Migrate from your legacy keys to the new rich authentication keys to:
- Reduce incidents of unauthorized access
- Create multiple keys
- Seamlessly rotate keys without any service disruption
- Create IP allowlists restricting access to your account to specific IP addresses
- Benefit from GitHub secret scanning (coming soon!)
As part of this update, we will also deprecate legacy user keys by March 1, 2025, and legacy app keys at the beginning of 2026.
Improving your account security is easy. It takes minutes to update to rich authentication keys in your dashboard and replace your current legacy key in your codebase. You can learn more in our
documentation.
If you have any questions or need help with the process, please feel free to reply to this email.
Thanks,
Team OneSignal