> ## Documentation Index
> Fetch the complete documentation index at: https://handbook.polar.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# API Tokens and System Credentials

> How we request, track, review, and revoke credentials used by Polar's systems.

## Inventory

The [System Credentials sheet](https://docs.google.com/spreadsheets/d/15RCxSWdOV-Wi7vXVNP-9n67A0IJUJIp1I2aFJsryPik/edit?usp=sharing) tracks system credentials in circulation, including API tokens and credentials for service accounts and infrastructure, with these fields: **Service**, **Owner**, **Creation Date**, **Expiration Date**, **Access Scope**, **Purpose**, **Environment**, **Investigate**, and **Original Request**.

Each entry identifies a named human owner and links to the approved Linear request in **Original Request**. Use **Purpose** to identify the component or system that needs the credential.

## Request

To request a system credential, submit the [request form](https://linear.app/polarsh/team/PLR/new?template=aad8b13a-6c51-4684-aad7-be4649f7409a) in Linear. Specify the vendor, required permissions or scope, and purpose.

The request is assigned to the respective vendor owner for review and approval. **Do not create the credential before the vendor owner approves the request.** The owner adds the new credential to the System Credentials sheet before granting access.

## Revoke

When a component is removed from the system or access is no longer required, **immediately revoke** any credentials that are no longer needed. Update the inventory to reflect the revocation.

## Quarterly review

Every quarter, the engineering leadership team reviews the inventory. For each vendor, go through the existing system credentials and reconcile them with those listed in the System Credentials sheet. Update the inventory and immediately revoke unused or stale credentials.

A [recurring issue in Linear](https://linear.app/polarsh/issue/PLR-192) reminds the people responsible to perform this review.
