> ## Documentation Index
> Fetch the complete documentation index at: https://docs.primevault.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Setting up API user for production

> Set up a PrimeVault production API user: generate keys manually or with AWS KMS, register your public key, assign roles, and activate your API key.

When you're ready to go live, create a dedicated production API user in PrimeVault. Follow these steps to generate and register your keys, assign the right role, and activate the user securely.

## Steps

<Steps>
  <Step title="Generate a public-private key pair">
    You have two secure options:

    <CardGroup cols={2}>
      <Card title="Generate manually" icon="key" href="/getting-started/generate-key-pair">
        Use the SDK or OpenSSL to generate the key pair yourself.
      </Card>

      <Card title="Use AWS KMS" icon="shield-halved" href="/getting-started/api-user-aws">
        Generate and manage your key pair with AWS Key Management Service (KMS).
      </Card>
    </CardGroup>
  </Step>

  <Step title="Register your public key">
    Enter your public key in the PrimeVault UI when creating the API user.

    The private key must remain securely stored in your environment. You need it to initialize the API client in your code.
  </Step>

  <Step title="Assign a role">
    Choose **Admin** or **User**. To learn what each role can do, see [Permissions for API User](/getting-started/permissions-for-api-user).
  </Step>

  <Step title="Activate the API user">
    Approve the API user addition in the PrimeVault phone app. The API user then becomes active.
  </Step>

  <Step title="Save your API key">
    Copy the API key and save it as an environment variable. You need it to initialize the SDK or API client.
  </Step>

  <Step title="Clean up test users">
    Remove or deactivate any API users used only during testing.
  </Step>
</Steps>

<Warning>
  Never hardcode your API key or private key in source code. Store them in environment variables or a secrets manager.
</Warning>

## Related

<CardGroup cols={2}>
  <Card title="Testing setup" icon="flask" href="/getting-started/api-user-testing">
    Try the flow with a dedicated test API user first.
  </Card>

  <Card title="Permissions" icon="lock" href="/getting-started/permissions-for-api-user">
    Understand Admin and User roles.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.