How to create a read-only Stripe API key (restricted key)
Create a Stripe restricted key with Read-only permissions to share revenue data safely with a buyer, accountant or tool. Step by step, and how to revoke it.
To create a read-only Stripe API key, go to Developers → API keys → Create restricted key in
the Stripe Dashboard, give the key a name, set the resources you want to share to Read and
leave everything else as None, then click Create key. The key starts with rk_live_. It
can look at the data you allowed and nothing else: it can't charge customers, issue refunds or
trigger payouts.
This is the safe way to give a buyer, an accountant, an analytics tool or a revenue verification
service access to your Stripe data. Never hand anyone your secret key (sk_live_), which can do
everything in your account.
What is a Stripe restricted API key?
A restricted API key is a Stripe secret key with permissions you choose, resource by resource. Each resource (Customers, Subscriptions, Charges and so on) is set to None, Read or Write. Stripe's own documentation recommends restricted keys "wherever possible" instead of unrestricted secret keys, especially when sharing access with a third party (Stripe docs: restricted API keys).
Secret key (sk_live_) |
Restricted key (rk_live_) |
|
|---|---|---|
| Access | Everything in the account | Only what you allow |
| Can move money | Yes | Only if you grant Write on those resources |
| Safe to share with a third party | No | Yes, with Read-only permissions |
| Can be scoped per use | No | Yes, one key per tool or person |
Note that Write includes Read: a resource set to Write can also be read. For a read-only key, nothing should be set to Write.
How do I create a read-only restricted key, step by step?
- Open the API keys page in the Stripe Dashboard: Developers → API keys, or go straight to dashboard.stripe.com/apikeys/create.
- Check you are in live mode, not a sandbox or test mode. A test-mode key (
rk_test_) only sees test data. - Click "Create restricted key". If Stripe asks how you will use the key, choose the option for sharing with a third party or building your own integration; both lead to the permission form.
- Name the key after who or what will use it, for example
Buyer due diligence - Oct 2026. One key per person or tool makes it easy to revoke one without breaking another. - Set permissions. Every resource starts at None. Change only the ones you need to Read.
- Click "Create key" and complete the two-factor check Stripe sends you.
- Copy the key and send it through a secure channel. Stripe only shows the full key once.
- Add a note in the dashboard recording who has it, so you remember to revoke it later.
Which permissions does a read-only key need?
Give the fewest permissions that do the job. What you need depends on who is reading:
| Purpose | Resources to set to Read |
|---|---|
| Revenue and MRR analysis | Subscriptions, Customers, Prices, Products, Invoices |
| Revenue totals and payouts | Balance, Charges, Refunds, Payouts |
| Buyer due diligence | All of the above |
| Dispute and fraud review | Disputes, Charges |
To connect a startup to VerifyArr, the setup screen lists exactly the resources to set to Read: Balance, Charges, Customers, Products and Refunds under Core; Invoices, Prices and Subscriptions under Billing; and read access to your own account details under Connect. If you miss one, it tells you which after you paste the key.
Is it safe to give someone a read-only Stripe key?
It is far safer than any alternative, but it is still access to real data. A read-only key can't move money or change anything, but it can read what you allowed, and Customers access includes customer names and email addresses. Before sharing one:
- Only grant what is needed. If someone only needs revenue totals, they don't need Customers.
- Share it securely, not in a public channel or a shared document.
- Revoke it when the job is done, for example after due diligence ends.
- Check whether the receiving service stores it encrypted and whether it rejects keys that can write. VerifyArr refuses full secret keys outright, refuses restricted keys with write access, and stores accepted keys encrypted.
If a buyer asks for dashboard access instead, Stripe also lets you invite them as a team member with the View only role, which works for a short due diligence review.
How do I revoke or change a restricted key?
On the API keys page, click the ⋯ menu next to the key:
- Edit key to add or remove permissions.
- View request logs to see every request made with the key. A useful audit trail if you want to know what a third party actually looked at.
- Delete (or expire) the key to cut access immediately. Anything using it stops working.
Common mistakes
- Sharing the
sk_live_secret key because it is the one on the first screen. Never do this. - Creating the key in test mode. The key works but shows no real revenue.
- Setting a resource to Write "just in case". Write includes the ability to create, update and delete. A reader never needs it.
- Using one key for everything. If one tool or person no longer needs access, you have to break the others to revoke it.
- Forgetting to delete it. Keys don't expire on their own.
Frequently asked questions
Does a restricted key expire?
No, it stays valid until you delete or expire it in the dashboard.
Can a read-only key see card numbers?
No. Stripe never exposes full card numbers through the API to anyone. With Customers or Charges access a key can see details such as the card brand and last four digits.
Why does my key start with rk_test_?
You created it in test mode or a sandbox. Switch to live mode and create the key again.
Can I use a restricted key to prove my revenue to buyers?
Yes. Giving a buyer read-only access lets them calculate MRR themselves instead of trusting a screenshot. See how to verify a startup's revenue before you buy it for what buyers do with it. If you'd rather not hand a key to every buyer, connect it once to a verification service that shows the numbers publicly.
VerifyArr uses one read-only restricted key to read your subscriptions and balance transactions, recalculates MRR, growth, churn and customer count every hour, and shows them on a public startup page that buyers trust. Connect your Stripe account in about a minute; it is free.
Buy and sell startups on revenue nobody typed in.
Every figure is read hourly from Stripe or RevenueCat with a read-only key. Listing is free.
More articles
How much is a SaaS worth? Small SaaS multiples in 2026
Small SaaS businesses usually sell for 3x to 5x annual profit or 1x to 3x annual revenue. How to pick a multiple, with examples at $1k, $5k and $20k MRR.
How to prepare your SaaS for sale: a 90-day checklist
Preparing a SaaS for sale means clean revenue data, documented operations, a handover list and a due diligence pack. A 90-day checklist for founders.