Bitfocus AS
logo
logo
Bitfocus AS
logo
logo
Sign upSign in

Loading...

Bitfocus

Subscribe to our newsletter

The latest news, articles, and resources, sent to your inbox.

FacebookInstagramGitHubYouTubeLinkedIn

Products

  • Buttons
  • Companion

Integrations

  • Supported Devices
  • Developer Community
  • Connection Development

Support

  • Support Overview
  • Documentation
  • Video Tutorials
  • Community Forum

Sales

  • Resellers & Integrators
  • Buttons Pricing

Updates

  • Case Studies
  • Events & Trade Shows
  • Press Releases
  • Product Updates
  • Webinars

Legal

  • Legal Overview
  • Privacy Policy
  • Buttons EULA
  • Terms & Cookie Policy

Company

  • About us
  • Press kit
  • Careers

© 2026 Bitfocus AS. All rights reserved.

Secure and monitor the Control API
Docs for
Overview
Getting started
What is Bitfocus Buttons?
Install Buttons and get started
Manage your Buttons license
Activate Buttons offline
Find your way around Buttons
Create your first backup
Add an ATEM connection
Choose a control method
Choose an installation path
Install Buttons on Debian or Ubuntu
Understand HA clustering
Kubernetes HA
Update or remove Buttons
Positions
Understand positions
Create a position
Add controls and sections to a position
Create your first button
Use a connection's presets
Build more capable button actions
Add more feedback to a button
Organize controls in a section
Shift Section
Organize controls with a Folder Section
Add a Popover Section
Build and reuse a Shared Section
Build a Router Section
Understand Custom Routers
Custom Router panel
Surfaces
Surface compatibility
Add and attach a surface
Device orientation
Connections
Update a connection's module safely
Monitor and troubleshoot a connection
Router integrations
VideoHub and AJA KUMO
Utah Scientific BPS
Generic SW-P-08
Nevion VideoIPath
Arkona BLADE//runner
Routing
Physical routing
Configure ports and labels
Take a physical route
Understand route status
Topology graph
Routing Presets
Get started with virtual routing
Configure Nested Shapes
Reverse routing
Tielines
Routing Projects
Routing settings
Troubleshoot a route
Tally
Understand the Tally system
Send ATEM tally and labels to a UMD
Interpret Active Tally state
TSL/UMD connections
Diagnose tally problems
NMOS
Understand NMOS in Buttons
Connect Buttons to an NMOS Registry
Built-in Registry Server
Configure NMOS connections
Discover and adopt
Browse the NMOS inventory
Manage NMOS multicast addresses
Diagnose NMOS problems
Understand Cuelists
Build a Cuelist
Read and advance a running Cuelist
Control a Cuelist from a Position
Workflows
Understand workflows
Build your first workflow
Reuse a group of workflow nodes safely
Troubleshoot a workflow
Recipes
Sequence a timed automation
Call an HTTP endpoint from a workflow
REST endpoint
Use variables
Understand variable scope
Understand nested variables
Update expressions for v1.8
Plan and use Tags
Access
Create and manage users
Create roles and assign permissions
Grant access to specific resources
Show different controls by role
Sessions
Set up PIN and NFC sign-in
SSO
Get started with SSO
Connect a generic OIDC provider
Connect LDAP or Active Directory
Map identity claims to roles
Secure a Buttons deployment
Integrations
External control
Connect to Bitfocus Listener
USB Relay
Install USB Relay on Windows
Install USB Relay on macOS
Install USB Relay on Linux
Install USB Relay on a Raspberry Pi
Get started with the Control API
Secure and monitor the Control API
Control API reference
API reference
Administration
Enable and manage installable features
Services and health
Configure and monitor scheduled backups
Restore a backup and verify it
Export or import Buttons configuration
Store and rotate connection secrets
Replace the HTTPS certificate
HA backup and recovery
Settings
Collect support information
Reference
Glossary
Button Inspector reference
Network ports reference
Expressions
Internal actions reference
Routing Presets panel reference
Startup configuration reference
Workflow nodes
Connection workflow nodes
Workflow workflow nodes
Internal workflow nodes
Position workflow nodes
API workflow nodes
Utility workflow nodes

Loading...

Previous
← Get started with the Control API
Next
Control API reference →
Contact support →
You are viewing documentation for Buttons 1.8.See the docs for Buttons 1.6
Buttons/API/Secure and monitor the Control API

Secure and monitor the Control API

Every API key can help an integration do exactly what it needs and nothing more, but that only holds if you configure permissions deliberately, watch for signs of misuse, and know what to do when something looks wrong. This page covers the permission model, rate limiting, monitoring requests, and responding when a key is behaving badly.

How API key permissions work#

An API key isn't a separate access system: creating one builds an internal role and grants it exactly the permissions you selected, using the same permission model as a user Role. This means:
  • A key can only be granted permissions its creator already holds. You can't use an API key to grant more access than your own account has.
  • Permissions can be changed after creation, from the same Set Permissions view used when the key was created: you don't need to issue a new key to narrow or widen its access.
  • Enable all permissions / Disable all permissions toggles the whole set at once, useful as a starting point before narrowing to specifics.
Keep every key scoped to what its integration actually does. A key with broader access than it uses is a bigger problem the moment it leaks.

Rate limiting#

Rate limiting is configured system-wide, not per key, using a token-bucket model with short bursts allowed. The default allows 50 requests per second; you can adjust this from the Rate limiting control in Settings → API, up to a maximum of 1000 requests per second, or turn limiting off entirely.
Each key is tracked against this limit independently: one key being rate-limited doesn't affect another. A request that exceeds the limit gets a 429 Too Many Requests response, along with rate-limit headers indicating when to retry.

Monitor activity#

The Control API Requests log shows every request made through the API in real time: client address, method, path, and status code for each one. This is the fastest way to notice something worth investigating: a burst of requests from an address you don't recognize, repeated failures against endpoints a key shouldn't be touching, or a spike right before something unexpected happened in Buttons.
A key's own detail view also shows Last used, useful for confirming whether a key is actually still in active use before you consider revoking it.

Respond to misuse#

  1. Open Control API Requests and confirm what the suspicious activity actually is: which key, which endpoints, from where.
  2. Open that key's detail view and select Revoke key. Revocation is immediate and can't be undone: every request using that key fails afterward with 401 Unauthorized.
  3. Issue a new, appropriately scoped key if the integration still needs access, rather than reusing the old value anywhere.
  4. If the exposure was broader than one key (for example, a shared machine or repository), review every key for unfamiliar activity, not just the one you already suspect.

If you get stuck#

What you see
What to try
Legitimate requests are being rate-limited.
Raise Requests / sec in Settings → API, or split heavy integrations across more than one key so each stays under the limit independently.
You can't tell which key is generating unexpected traffic.
Cross-reference the client address and path in Control API Requests against each key's own Last used timestamp and granted permissions.
A key seems to have more access than intended.
Open Set Permissions on the key and remove anything beyond what its integration actually uses: this takes effect without reissuing the key.

Where to go next#

  • Get started with the Control API, for creating and using a key.
  • Control API reference, for the full endpoint list, schemas, and versioning policy.
  • Secure a Buttons deployment, for API access as part of a broader security baseline.

Was this helpful?

Was this helpful?

0 of 0 users found this page helpful