Skip to main content
Feedback

Keyless Plans

Updated 23 July 2026

Use a Keyless Plan to call a deployed API without an API Key.

The API Gateway requires you to include the API Key in the X-API-KEY header. Use Keyless Plans primarily when you need to bypass this required header in the Shared Web Service SOAP Client connector. Boomi recommends Keyless Plans only for the scenario when existing applications do not insert the required X-API-KEY header and you cannot reconfigure them.

caution

Boomi recommends against setting a Keyless Plan on any deployed API with an authentication of API Key Controlled. A Keyless Plan on an API Key Controlled authentication removes all authentication on the deployed API, meaning that your deployed API becomes unsecured and at risk of misuse.

With a Keyless Plan enabled, you can call an API with a valid API Key or without one. In the case of an API call without a valid API Key, a subscription is not necessary. Because rate and quota calculations use the client IP address, you should review your usage limits on any deployed API that uses a Keyless Plan.

You can set up Keyless Plans using the GraphQL Deployed API category. You can use the Gateway category Gateway Update mutation (gatewayUpdate) for all deployed APIs on the API Gateway.

Alternatively, you can also set a Keyless Plan for a plan on the Deployed APIs Plans page. To do this, turn on Use a Keyless Plan option and then select the plan you want to use as Keyless.

Tips for working with the keyless plans GraphQL mutations

There are three fields to specify for a Keyless Plan mutation. You must include the apiDeploymentId. planIds and keylessPlanId are optional. However, if you have planIds and leave the planIds field empty, the mutation deletes API Plan associations. Include the Plan IDs that you do not want to delete in the planIds field. The mutation deletes any IDs not included in the planIds field.

To add new or additional API Plan associations to the Plan IDs, include your existing Plan IDs and the new Plan IDs that you want to add to the planIds field. If you do not include all Plan IDs that you want to keep, the mutation deletes any IDs not included in the planIds field.

On this Page