API Keys
Manage authentication keys for Device Farm automation.
Overview
API Keys are used to authenticate automated tests with Device Farm. Each key is tied to your organization and can be used for Appium/WebDriver connections and test event reporting.
Key Format
Device Farm API keys follow this format:
df_auto_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Keys are 40 characters long and prefixed with df_auto_.
How to Use
Method 1: HTTP Header (Recommended)
Include the API key in the X-API-Key header:
curl -X POST "https://api.rabbitqa.com/df/wd/hub/session" \
-H "X-API-Key: df_auto_xxxxx" \
-H "Content-Type: application/json" \
-d '{"capabilities": {...}}'
Method 2: Capability
Include the API key as a capability (useful for Appium clients):
{
"platformName": "Android",
"appium:automationName": "UiAutomator2",
"df:apiKey": "df_auto_xxxxx"
}
Authenticated Endpoints
These endpoints require API key authentication:
| Endpoint | Description |
|---|---|
/df/wd/hub/session | Create automated test |
/df/wd/hub/session/{id}/* | All WebDriver/Appium commands |
/api/automation/sessions/{id}/test-events | Report test execution events |
Security Best Practices
Never Commit Keys Never commit API keys to version control. Use environment variables or secret management systems instead.
Use Environment Variables
Store API keys in environment variables:
export DEVICE_FARM_API_KEY=df_auto_xxxxx
Rotate Keys Regularly
Create new keys periodically and revoke old ones. This limits the impact if a key is compromised.
Use Separate Keys
Create separate keys for different environments (dev, staging, prod) and different team members for better audit trails.
Key Management
| Action | Description |
|---|---|
| Create | Generate a new API key with a descriptive name |
| View | See key details, creation date, and last used timestamp |
| Revoke | Permanently disable a key (cannot be undone) |
| Regenerate | Create a new key value while keeping the same name |
Note: The full API key is only shown once when created. Make sure to copy it immediately and store it securely.