> For the complete documentation index, see [llms.txt](https://bugrecon.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://bugrecon.gitbook.io/docs/features-list/api-keys.md).

# API Keys

The **API Keys** page lets you store and manage credentials for external services used by BugRecon. Keys are stored securely (encrypted) and are only used by the backend when running scans or sending notifications. You never need to paste these credentials into scan parameters manually.

![AI keys](https://1075470145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV2n4UTcrS4SHhY2NTi0v%2Fuploads%2Fgit-blob-2e41daae2c673120bdea41cb38a4dd645d639edb%2Fapikeys.png?alt=media)

![Discord webhook](https://1075470145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV2n4UTcrS4SHhY2NTi0v%2Fuploads%2Fgit-blob-e1b52b1a3888b4ffb447535f70424cda901133c8%2Fapikeys2.png?alt=media)

***

## Why API keys?

* **Subdomain enumeration:** Internal tools can use many data sources (Shodan, VirusTotal, Censys, SecurityTrails, etc.). Adding API keys for these services improves subdomain discovery when you run a **Subdomain scan** (Premium and above).
* **Notifications:** A Discord webhook URL is used to send you alerts (scan completion, CertStream detections, integration sync results). You configure it once under **Notification Services**.

You only need to add keys for the services you want to use; the application works without them, but with reduced coverage or no notifications.

> **Security note:** The security of your data is very important to us. All sensitive information, including API keys, is stored securely and encrypted. These credentials are not accessible by application administrators or system administrators. Only your account can access them when used by the application.

***

## Where to manage API keys

1. Click your **profile/avatar** in the navbar.
2. Click **API Keys**.
3. You see **categories** (e.g. Notification Services, Subdomain enumeration keys). Expand a category to see the list of services.

***

## Categories and services

### Notification Services

* **Discord:** Webhook URL for your Discord channel. Used for scan notifications, CertStream alerts, and (when configured) integration sync results.
  * Field: **Webhook URL** (required).
  * You create the webhook in Discord: Server → Channel → Edit → Integrations → Webhooks.

### AI keys

The **AI scan** uses these keys to analyze your scan data and suggest prioritized targets. You need at least one AI key configured to run an AI scan.

* **OpenAI** - Your OpenAI API key; you can choose from supported models (e.g. GPT-4o, GPT-4.1, GPT-5).
* **Anthropic** - Your Anthropic API key for Claude models (e.g. Claude Sonnet, Claude Opus).
* **OpenRouter** (or compatible) - For services that offer many models through one key; you can optionally set a custom URL.

You can mark one key as **default** so it is used automatically when you run an AI scan. The API Keys page shows the fields to fill and, where supported, lets you pick the model.

### Subdomain enumeration keys

This category contains many providers used for passive/active subdomain discovery. Examples (non-exhaustive):

* **Shodan, Censys, VirusTotal, SecurityTrails**
* **BinaryEdge, AlienVault OTX, GitHub, GitLab**
* **Chaos (ProjectDiscovery), CertCentral, Hunter.io, IntelX, LeakIX**
* **PassiveTotal (RiskIQ), ZoomEye, FOFA, and many others**

Required fields are marked (e.g. with \*). Placeholders or labels in the UI indicate the expected format (e.g. "Account Name", "App ID").

***

## Add or update a key

1. Open **API Keys** and expand the category.
2. Find the service (e.g. Discord, Shodan).
3. Fill in the required (and optional) fields. For password-type fields, use the show/hide eye icon if you need to check what you typed.
4. Click **Save** (first time) or **Update** (if the key already exists).
5. A success message confirms the key was stored. **Last updated** date is shown for that service.

If you leave a required field empty, you will see an error and the key will not be saved.

***

## Delete a key

1. Open **API Keys** and expand the category.
2. Find the service that has a key configured.
3. Click **Delete** and confirm.
4. The key is removed. The backend will no longer use it (e.g. no Discord notifications if you delete the Discord webhook; subdomain sources will skip that provider).

For **Discord**, deleting the key also triggers removal of the corresponding notify configuration on the server so that no notifications are sent to that webhook.

***

## Security and storage

* Keys are stored **per user** and **encrypted** in the database. Other users cannot see your keys.
* The UI shows a mask or placeholder for existing password-type values when you reopen the form; you can replace them by typing a new value and saving.
* Do not share your API keys or webhook URLs. If a key is compromised, revoke it in the provider’s dashboard and set a new one in BugRecon.

***

## No keys configured

If you have not configured any keys, the API Keys page shows an empty state message. Expand a category and add at least one service (e.g. Discord for notifications, or a subdomain source for better discovery) as needed.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://bugrecon.gitbook.io/docs/features-list/api-keys.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
