# Where is the Allow\_user\_api\_key setting enabled?

**URL:** https://meta.discourse.org/t/allow-user-api-key/401671
**Category:** Support
**Created:** [April 28, 2026, 6:49am UTC](https://meta.discourse.org/t/allow-user-api-key/401671 "2026-04-28T06:49:07Z")
**Posts on this page:** 1
**Showing post:** 9

<div class="post-metadata">

### Author: ![NateDhaliwal](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/natedhaliwal/32/313494_2.png) [@NateDhaliwal](https://meta.discourse.org/u/NateDhaliwal)
#### Post date: [April 28, 2026, 1:07pm UTC](https://meta.discourse.org/t/allow-user-api-key/401671/9 "2026-04-28T13:07:34Z")

</div>

I see. Have you seen this?

> [@User API keys specification](https://meta.discourse.org/t/user-api-keys-specification/48536):
>
> Discourse contains a system for generating API keys per user if a very specific protocol is followed. This feature facilitates “application” access to Discourse instances without needing to involve moderators. High level description At a high level: Client (desktop app, browser plugin, mobile app) generates a private/public key pair and return url Client redirects to a route on discourse giving discourse its public key Discourse gets approval from user to use app Discourse generat…

---

_[View the full topic](https://meta.discourse.org/t/allow-user-api-key/401671)._
