1
Enable API Key Access
Go to Settings › Security › Security policies and make sure Enable API key creation under Other settings is turned on. If it is disabled, contact your workspace owner to enable it.

2
Start a New API Key creation
In Settings › API keys, click New API key. Enter a name, select a team role, an expiration period, account access, and (optionally) specify allowed IP addresses.

3
Generate or Supply Your Key Pair
Bron uses asymmetric keys. You have two options:
When you supply your own JWK, it must meet these requirements:
Example JWK
How to generate a key?
How to generate a key?
You can use any library that supports ES256 and JWK. For example:
- JavaScript (Node.js): panva/jose
- Java: Nimbus JOSE + JWT
- Or any other ES256-compatible library.
API key roles
The team role picked at creation decides what the key can do. Every role is scoped to the accounts selected for the key.
Reads cover workspaces, accounts, balances, addresses, transactions, quotes (
swap-route, intents/quote) and the address book. Signing covers signing requests and hot signer registration; a Transaction Operator key creates transactions that a person or an MPC Hot Signer key then signs.
Transaction types a Transaction Operator or Full Access key can create with POST /workspaces/{workspaceId}/transactions (and POST /workspaces/{workspaceId}/intents for intents):
defi and defi-message (WalletConnect), earn-*, fiat-*, loyalty-* and bron-lock-* transactions are created from the Bron app only.