Skip to main content
Every PrimeVault API user is assigned a role that controls what it can access and do within your organization. Choose Admin or User when you create the API user.

Roles for API users

Admin

  • Has read access to all vaults within the org by default.
  • Can create vaults and manage contacts.

User

  • Must be assigned to one or more vaults as a signer or viewer.
  • Cannot create vaults directly.
  • Ideal team members with specific operational roles.

Best practices

  • Always assign the minimum privileges each API user needs.
  • Regularly review and update policy templates to align with org changes.
For most integrations, start with a User role assigned to only the vaults it needs, then expand access if required.

Testing setup

Create a dedicated test API user.

Production setup

Create and activate a production API user.