The Control API can help you drive Buttons from your own scripts, show-control systems, or automation tools: using the same underlying capabilities the web interface uses, scoped to exactly what that integration needs and nothing more. This guide creates a scoped key, makes a first request with it, confirms it in the request log, and revokes it when you're done testing.
Warning
Never embed a real API key in a script you share, commit to source control, or paste into a support request. Anyone holding the key has whatever access you granted it.
Enter an API key name, such as Broadcast Automation, and an optional description.
Select Next to open Set Permissions.
Select only the specific permissions this integration actually needs: you can only grant permissions you already hold yourself, and you can change this later without creating a new key.
Select Create.
The key's actual value is shown exactly once, with a reminder that this token will only be shown once. Copy it now. Afterward, only its prefix stays visible for identification, not the full value.
Use a read-only request first, so a mistake can't change anything:
GET /control/<domain>/v1/...Authorization: Bearer <your key>
Replace <domain> with the area you're working with: for example, a request scoped to surfaces lives under /control/surface/v1/.... A valid key with insufficient permission for that request returns 401 Unauthorized; the same status covers a missing or malformed key.
The full request and response shapes are documented at /control/docs, generated directly from the running system rather than maintained by hand: check there for the exact endpoints, parameters, and schemas available to your version of Buttons.
Open Settings → API and select API Docs, or open the key's own detail view to see Last used. For a live view of requests as they happen, open the Control API Requests log: each entry shows the client address, method, path, and status code for every request made through the API, across all keys.
Open the key's detail view, or select it from the list.
Select Revoke key (or Revoke from a multi-select).
Confirm: revocation cannot be undone, and it takes effect immediately. Any request using this key afterward fails with 401 Unauthorized, reported as the key having been revoked.