Library third-party API settings
Third-party API settings hold protected credentials that services in the library can use by default for supported integrations. Open Library settings, then Third party APIs.
These are credentials for services to call external products. They are different from Govforms API keys, which allow an external system to call Govforms.
Understand precedence
flowchart TD
A[Service needs a supported external API] --> B{Service-level key set?}
B -->|Yes| C[Use service-level key]
B -->|No| D[Use library default key]
C --> E[Call external API]
D --> EA service-level credential takes precedence over the library default for that service. Changing a library key therefore affects only services that have not set their own override. Before rotating a key, inventory both locations.
Configure supported credentials
The page can hold credentials for supported mapping and notification integrations. Each value is treated as a secret: after it has been stored, the Builder shows a masked value and provides a controlled way to clear it rather than displaying it again.
For a mapping integration, give the key only the place-search or map-tile products the service uses. Where the provider issues a paired key and secret, rotate them together.
For a template-based notification provider, make sure the key can access only the intended account or message templates. Keep template IDs in the action or authentication setting that uses them; keep the API credential here.
Do not paste credentials into page content, Liquid templates, action URLs, screenshots or change descriptions.
Apply to QA and Production
The page shows whether the default settings have been applied and records the last application user and time for each environment.
- Enter or rotate the credential.
- Apply it to QA.
- Test the real map, email, SMS or sign-in journey in QA.
- Confirm which services use the library default and which override it.
- Apply to Production after approval.
- Run a controlled live smoke test that does not send unintended messages or expose personal data.
Applying the library API configuration is separate from deploying a service version. If a new action depends on a new credential, apply the credential first, then deploy and test the service.
Rotate or clear a key
Record the owner, provider account, purpose, dependent services and expiry. For a planned rotation, create the replacement at the provider, update QA, test, update Production and then revoke the old value. Keep the overlap short.
Use the clear control only when you intend services without their own override to fall back to no credential or a platform default. Clearing the Builder value does not revoke it at the provider; revoke or delete it there as well.
Troubleshoot
If an integration still uses the old value, check:
- whether the new setting was applied to the correct environment;
- whether the service has its own override;
- whether the provider key has access to the required product or template;
- whether the provider has activated the replacement credential;
- whether the service version containing the integration has been deployed.
