Manage restricted access keys
Use the Restricted Access Keys page to manage access keys for private catalog views created by the Adobe Commerce Optimizer Connector for B2B. The connector synchronizes B2B shared catalog configurations from Adobe Commerce to Adobe Commerce Optimizer.
Audience and availability audience
The Restricted Access Keys page is available to Adobe Commerce on Cloud Infrastructure and on-premises merchants who use B2B shared catalogs with the Adobe Commerce Optimizer Connector for B2B. The connector installs and enables the page automatically.
When a catalog view is first created for a shared catalog, the connector automatically generates and assigns one key. Use this page to view that key, and to create, assign, or delete additional keys.
Access the Restricted Access Keys page access-restricted-access-keys-page
From the Admin area, navigate to System > Data Transfer > Restricted Access Keys.
This page lists every key regardless of whether it’s assigned to a catalog view. To assign a key to a specific catalog view, use the Edit Restricted Access Keys action on that catalog view instead. See Assign keys to a catalog view.
Restricted Access Keys summary restricted-access-keys-summary
The grid contains one key per row.
Manage keys manage-keys
- Create Key—Generates a new, unassigned key pair. Commerce generates the key pair and stores the private key. The public key isn’t registered with Adobe Commerce Optimizer until you assign the key to a catalog view.
- View Public Key—Opens a read-only view of the key’s public key, so you can copy it to re-register or re-sync the key if needed. The private key is never displayed.
- Delete—Removes the key and revokes its remote registration in Adobe Commerce Optimizer. Storefront tokens already issued with this key remain valid until they expire. This action can’t be undone.
Create a key
On the Restricted Access Keys page, create a key by selecting Create Key.
Commerce generates a new key pair and stores the private key. The Restricted Access Keys table updates with a new key entry showing the unique key ID. Use this Key ID when you assign the key to a catalog view.
The public key is not registered with Adobe Commerce Optimizer until you assign the key to a catalog view. After registration, the Restricted Access Keys table entry is updated to show the catalog assignment and expiration date.
Assign or remove restricted access keys assign-keys-to-a-catalog-view
Assign or unassign keys from a catalog view, not from the main Restricted Access Keys grid. You can make this change from either the shared catalog’s Catalog Views tab or the associated company’s Catalog Views section — both list the same catalog views and current key assignments.
A catalog view must have at least one key and can have at most three. If you try to assign a fourth key, the save fails with a message telling you to remove one first.
-
Open the Catalog Views grid for the catalog view you want to update, using one of the following paths:
- From the shared catalog — On the Admin sidebar, go to Catalog > Shared Catalogs. For the shared catalog, select General Settings from the Action column. Then, in the Shared Catalog Information panel, select Catalog Views.
- From the company — On the Admin sidebar, go to Customers > Companies. For the company, select Edit from the Action column. Then expand the Catalog Views section.
Both grids list the catalog views created for the shared catalog assigned to the company, including their assigned keys.
-
Select Edit Restricted Access Keys for the catalog view you want to update.
{width="500" modal="regular"}
-
In the Access Keys field, select an unassigned key by the Key ID value.
Keys already assigned to a different catalog view are labeled accordingly.
-
Select Done to assign the key to the catalog view.
-
To remove a key from the Access Keys field, select the
xin the key name entry to remove it. -
Click Save.
Key selection and rotation key-selection-and-rotation
When more than one key is assigned to a catalog view, Adobe Commerce automatically uses the assigned, unexpired key with the latest expiration date to sign tokens.
To change the default expiration period applied to newly created keys, go to Stores > Configuration > Services > ACO Restricted Access Keys > Provisioning > Default key lifetime (days). See Services > ACO Restricted Access Keys.
Known limitations known-limitations
-
There is no active or status indicator on the main Restricted Access Keys grid.
You can see the link status on the Edit Restricted Access Keys page. Use the dropdown to view available keys and their status. If a key is assigned to a catalog view, it is linked. If it is not assigned, it has no status. You can assign those keys to the catalog view you are editing.
In the Catalog View Sync Status page, you can see keys linked to a catalog view from the catalog view detail page (View details action). The detail page also shows the key history, including when it was assigned or unassigned from a catalog view.
-
Automatic key rotation is not available yet.