Client Keys/ Scope Read-Only Miners for Hosted Clients, Not Admin Access
Hosted clients need to see their own miners. That is not a reason to send them an administrator login. ItsMiner Client Keys live under Customers > Client Keys. A farm administrator creates the key and limits read-only visibility to miners that already belong to that client and have been added to the key.
This guide is for farm administrators. One boundary should be clear first: an Observer Page is for a person checking numbers in a browser. A Client Key is for the client’s own system, using the same read-only miner scope. Neither path can change configuration, reboot miners, or run Load Control. Write operations stay on the host side.
Confirm who can create a key, and where the miners come from
Client Keys are visible only to farm administrators. The miner picker is not the whole farm. When you create a key, the system only lists miners already assigned to that client. Machines that belong to someone else do not appear. On a given farm, each client can have only one key.
Feature: Assign miners first under Customers > Assign Miners, then create the key. Assignment decides ownership. Visible miners on the key decide which of those machines the client can actually read. Both layers have to be true.
Use it for: Splitting “who owns this miner” from “which miners the client’s system can see,” so a newly issued key does not expose the whole site.
If a target miner is missing from the picker, go back to Assign Miners and check ownership. Do not keep searching inside the key dialog.
Create by validity period, client, and visible scope
The steps are short. The order is not optional:
- Open Customers, then Client Keys (administrators only).
- Click Create Key.
- Choose the validity period and the client, set visible miners, then click Create.
- Copy the Client ID and Client Key immediately and store them. The key is shown once. After you confirm, share it with the client.
Feature: The key has read-only access to the visible miners. The client receives a Client ID and Client Key pair, not a back-office login.
Use it for: Letting the client’s own system pull status for its miners, without entering the admin console and without touching Load Control or miner operations.
After creation, manage scope and rotation
Once a key exists, the list supports four actions: edit visible miners, edit remarks, update the key, and delete it. After an update or delete, the old key is invalid immediately. The new key has to be shared with the client again.
Visible scope does not expand automatically when assignment changes. If client A already has a key and a new miner is later assigned to A, that miner does not join the key’s visible set until an administrator adds it. The other way around is automatic: if a miner already in the visible set is later assigned to another client, it is removed from that key’s visible miners.
Feature: Adding machines requires a manual update to visible miners. Transferring a machine to another client removes it from the old key. Remarks are there to record who received this key and which contract it belongs to, so rotation does not send the wrong credential.
Use it for: Checking assignment first, then the key scope, whenever a client adds machines, or miners move. That keeps another client’s hardware out of the feed, and keeps newly assigned hardware from staying blank.
An issuing rhythm you can adopt
- Before issue: Confirm the Customer module is on and the account is a farm administrator. Assign contract-scope miners to that client.
- First create: Set visible miners to the machines currently under that contract. Newly assigned miners will not join the key on their own.
- Handoff: Client ID and Client Key appear in full only at creation. Copy them, then send them through the secure channel your team already uses. Do not paste them into a public ticket or a group chat.
- Routine: After a client adds machines, add those miners to the visible set by hand. After a transfer, confirm the miner has left the old key.
- Incident: If a key leaks, staff change, or the contract ends, update or delete immediately. The old key fails at once.
A Client Key is not a way to log clients into the admin console. It is a way to write down a read-only scope: which machines belong to whom, which of those the client’s system may read, and when the credential is retired. Observer Pages are for people. Keys are for the client’s system. Load Control, restarts, and pool switches stay on site. Get the scope and the rotation right, and the transparency a hosted client wants does not turn into farm-wide access.
Contact us for a demo:
- Email: sales@powsell.com
- Telegram: @ItsMinerOfficial
Subscribe to ItsMiner's Blog
Get the latest posts delivered right to your inbox