VerifyArr
Blog

How to create a read-only Stripe API key (restricted key)

Create a Stripe restricted key with Read-only permissions to share revenue data safely with a buyer, accountant or tool. Step by step, and how to revoke it.

N
Naser
5 min read

To create a read-only Stripe API key, go to Developers → API keys → Create restricted key in the Stripe Dashboard, give the key a name, set the resources you want to share to Read and leave everything else as None, then click Create key. The key starts with rk_live_. It can look at the data you allowed and nothing else: it can't charge customers, issue refunds or trigger payouts.

This is the safe way to give a buyer, an accountant, an analytics tool or a revenue verification service access to your Stripe data. Never hand anyone your secret key (sk_live_), which can do everything in your account.

What is a Stripe restricted API key?

A restricted API key is a Stripe secret key with permissions you choose, resource by resource. Each resource (Customers, Subscriptions, Charges and so on) is set to None, Read or Write. Stripe's own documentation recommends restricted keys "wherever possible" instead of unrestricted secret keys, especially when sharing access with a third party (Stripe docs: restricted API keys).

Secret key (sk_live_) Restricted key (rk_live_)
Access Everything in the account Only what you allow
Can move money Yes Only if you grant Write on those resources
Safe to share with a third party No Yes, with Read-only permissions
Can be scoped per use No Yes, one key per tool or person

Note that Write includes Read: a resource set to Write can also be read. For a read-only key, nothing should be set to Write.

How do I create a read-only restricted key, step by step?

  1. Open the API keys page in the Stripe Dashboard: Developers → API keys, or go straight to dashboard.stripe.com/apikeys/create.
  2. Check you are in live mode, not a sandbox or test mode. A test-mode key (rk_test_) only sees test data.
  3. Click "Create restricted key". If Stripe asks how you will use the key, choose the option for sharing with a third party or building your own integration; both lead to the permission form.
  4. Name the key after who or what will use it, for example Buyer due diligence - Oct 2026. One key per person or tool makes it easy to revoke one without breaking another.
  5. Set permissions. Every resource starts at None. Change only the ones you need to Read.
  6. Click "Create key" and complete the two-factor check Stripe sends you.
  7. Copy the key and send it through a secure channel. Stripe only shows the full key once.
  8. Add a note in the dashboard recording who has it, so you remember to revoke it later.

Which permissions does a read-only key need?

Give the fewest permissions that do the job. What you need depends on who is reading:

Purpose Resources to set to Read
Revenue and MRR analysis Subscriptions, Customers, Prices, Products, Invoices
Revenue totals and payouts Balance, Charges, Refunds, Payouts
Buyer due diligence All of the above
Dispute and fraud review Disputes, Charges

To connect a startup to VerifyArr, the setup screen lists exactly the resources to set to Read: Balance, Charges, Customers, Products and Refunds under Core; Invoices, Prices and Subscriptions under Billing; and read access to your own account details under Connect. If you miss one, it tells you which after you paste the key.

Is it safe to give someone a read-only Stripe key?

It is far safer than any alternative, but it is still access to real data. A read-only key can't move money or change anything, but it can read what you allowed, and Customers access includes customer names and email addresses. Before sharing one:

  • Only grant what is needed. If someone only needs revenue totals, they don't need Customers.
  • Share it securely, not in a public channel or a shared document.
  • Revoke it when the job is done, for example after due diligence ends.
  • Check whether the receiving service stores it encrypted and whether it rejects keys that can write. VerifyArr refuses full secret keys outright, refuses restricted keys with write access, and stores accepted keys encrypted.

If a buyer asks for dashboard access instead, Stripe also lets you invite them as a team member with the View only role, which works for a short due diligence review.

How do I revoke or change a restricted key?

On the API keys page, click the ⋯ menu next to the key:

  • Edit key to add or remove permissions.
  • View request logs to see every request made with the key. A useful audit trail if you want to know what a third party actually looked at.
  • Delete (or expire) the key to cut access immediately. Anything using it stops working.

Common mistakes

  • Sharing the sk_live_ secret key because it is the one on the first screen. Never do this.
  • Creating the key in test mode. The key works but shows no real revenue.
  • Setting a resource to Write "just in case". Write includes the ability to create, update and delete. A reader never needs it.
  • Using one key for everything. If one tool or person no longer needs access, you have to break the others to revoke it.
  • Forgetting to delete it. Keys don't expire on their own.

Frequently asked questions

Does a restricted key expire?

No, it stays valid until you delete or expire it in the dashboard.

Can a read-only key see card numbers?

No. Stripe never exposes full card numbers through the API to anyone. With Customers or Charges access a key can see details such as the card brand and last four digits.

Why does my key start with rk_test_?

You created it in test mode or a sandbox. Switch to live mode and create the key again.

Can I use a restricted key to prove my revenue to buyers?

Yes. Giving a buyer read-only access lets them calculate MRR themselves instead of trusting a screenshot. See how to verify a startup's revenue before you buy it for what buyers do with it. If you'd rather not hand a key to every buyer, connect it once to a verification service that shows the numbers publicly.


VerifyArr uses one read-only restricted key to read your subscriptions and balance transactions, recalculates MRR, growth, churn and customer count every hour, and shows them on a public startup page that buyers trust. Connect your Stripe account in about a minute; it is free.

VerifyArr

Buy and sell startups on revenue nobody typed in.

Every figure is read hourly from Stripe or RevenueCat with a read-only key. Listing is free.

More articles