Using API keys to automate tasks

When a Verint service representative or developer integrates a new application, service, or bot with your WFO system, they may ask you for an API key. This key allows the integration to call the required Verint APIs securely.

What Is an API key?

An API key is a unique credential that identifies and authenticates a caller (application, service, bot, or workstation component) to Verint Workforce Optimization (WFO) Fifth generation Workforce Optimization solution that provides a full, end-to-end enterprise solution, including unified, enterprise-wide installation procedures, a centralized system management layer, organizational and user management, and a variety of applications and cross-application integrations.. Keys enable integrations to call Verint APIs securely without exposing user passwords.

A key ensures:

  • The system knows who is making the request.

  • The requester is authorized to access the appropriate Verint APIs.

Keys can be tenant-scoped (available to all users or features in a customer's tenant account) or user-scoped (restricted to the permissions of a specific user).

Keys do not automatically inherit capabilities beyond their configured scope.

API Key life cycle

Typically, API keys follow a life cycle: create → use → rotate → revoke.

  • Create: Generate a key for an integration that requires API access. Keys are enabled by default.

  • Use: Distribute the key securely to the requesting application/vendor.

  • Rotate: To minimize risk, replace keys on a cadence. The system automatically rotates Desktop keys. Rotation for the other key types is optional, and done by API request.

  • Revoke: Disable or delete keys that are unused, obsolete, or suspected to be compromised.

Expiration (non-Desktop)

For Custom, External, and Internal keys you can create keys that never expire or set an expiry date. When the expiry time is reached, the system disables the key and deletes it seven days later. The system checks expiry periodically, so a delay of up to two hours can occur.

Security Best Practices

  • Create the keys required for your system. Verint Services cannot create keys for you.

  • Share keys only through secure, encrypted channels—never in plain text by email or messaging.

  • Prefer user‑scoped keys when possible; monitor usage and revoke unused keys promptly.

  • Rotate keys regularly; treat keys as sensitive credentials and store them securely.

  • Understand that if a key is compromised, it can allow unauthorized access to sensitive data.

Types of WFO API keys and when to use them

Desktop API keys

API key scope (Tenant vs User)

API Keys page reference

Generate an API key

Display an API key value

Copy an API key