ARIN now accepts Reg-RWS API keys in a request header
ARIN's 28 July release added header-based API keys for its Registration RESTful Service. Keys sent as URL query parameters still work, but ARIN says that method will eventually be retired.
What changed
As part of its 28 July 2026 release, ARIN's Registration RESTful Service (Reg-RWS) began accepting API keys in a request header. ARIN explained the change in an 11 August blog post and repeated the advice in its September roundup: sending the key as a URL query parameter remains acceptable for now, but support for that method will eventually be retired, and ARIN recommends switching. No retirement date has been published.
Why it matters for BYOIP teams
Teams that automate registry records, such as reassignments, point-of-contact data or other registration tasks, often do it through Reg-RWS. Keys in URLs can end up in proxy logs, monitoring tools and shell history, so moving them to a header is a small change with a clear security benefit. This follows a similar credential change at the RIPE NCC (see related story).
What to check
- Search scripts and infrastructure code for Reg-RWS calls that pass the key in the URL (for example an
apikey=query parameter). - Third-party tools and provider integrations that call ARIN on your behalf.
- Logs that may already contain keys; rotate keys if they have been exposed.
Sources
- ARIN Bits, September 2026
ARIN · published 29 Sept 2026 · checked 30 Sept 2026
- Make the Switch to More Secure API Key Handling for Reg-RWS
ARIN Blog · published 11 Aug 2026 · checked 30 Sept 2026
- ARIN Online release, 28 July 2026
ARIN · published 28 Jul 2026 · checked 30 Sept 2026