12 days until 15 October 2026

Your Base44 API key stops working on 15 October 2026.

Every script, spreadsheet, automation and pipeline still sending the old header dies that day. No grace period, no warning, and an error message that will not tell you what went wrong.

I have been building on Base44 since early on and I have migrated my own estate. Here is the runbook, and here is the offer to do it for you.

Why it is not a two-line change

The header swap takes a minute. The rest does not.

Base44's instructions are correct and they are also the easy half. Here is the half that costs people their week.

There is no inventory, and Base44 will not give you one.

Their email says the logs show key activity on your account. It does not say what is using it. One key was pasted into scripts, sheets, CI secrets and other people’s tools over months, and finding every one of them is the job.

One key becomes many tokens.

Tokens are workspace-specific, and Base44 recommends one per tool. Three workspaces and four tools is twelve tokens, each with its own scope, permission and storage decision. That is credential management, not find-and-replace.

A personal token dies with its creator’s membership.

It acts as the person who made it and stops working if they leave the workspace. Every automation an agency runs inside a client’s workspace is a time bomb, and the documented fix is a workspace API key — owner or admin only, and on a higher plan.

The error message tells you nothing.

Tested live on 15 September 2026: no credentials, an invalid old key, and an invalid new token all return an identical 401 saying "you must be logged in", with a null request id. Nothing to diagnose with, and nothing useful to hand support.

It fails silently, at 03:00, weeks from now.

Nightly syncs, weekly reports, monthly invoice runs. No grace period and no warning banner after the date — you find out when the data is missing or a customer tells you.

One more, for the developers. As of 15 September 2026 Base44's own API reference still documents the old api_key header with no deprecation notice attached, and so does the account settings page. The migration instruction arrives by email; the reference you would naturally open still shows the header that stops working. If you copy from the reference, you will copy the wrong thing.

Do it yourself

The guide. Everything I would do, written down.

Not a summary of Base44's announcement. The actual runbook I work from, including the parts their documentation does not cover and the two places it currently contradicts itself.

Read it on the site, or take the download. Both, if you want one to work from and one to keep.

What is in it

  • The triage

    Seven questions that tell you whether this touches you at all.

  • The discovery sweep

    The grep, plus the twelve places that are not in your repo — Apps Script, CI secrets, host env vars, the contractor you forgot about.

  • The register

    The one document the whole migration runs on, with the column most people leave out: how you would know if it broke.

  • Token design

    Scope and permission per token, and the decision tree for when a personal token is the wrong credential entirely.

  • Header swaps for eight stacks

    curl, Node, Python, Apps Script, n8n / Make / Zapier, GitHub Actions, Postman — copy, paste, done.

  • The troubleshooting table

    Because a 401 here is identical whether you sent no credentials, the old header, or a bad token. Tested live.

  • The close-out list

    Including the step almost everyone skips, which is the one that saves you.

Price

£49

One payment. Updated free until the deadline, because Base44 is still changing its own documentation.

How you get it

  • Read it here, on the site, kept current.
  • Download a copy to keep and mark up.
  • Sign in first so the copy on the site opens for you afterwards.

Not sure you need it? Run the free check first — it takes two minutes and may tell you there is nothing to do.

Done for you

Or I do it, and you get on with your week.

Fixed scope, fixed price, agreed before the work starts. The caps on each tier are the point — they are what stops a small job quietly becoming a big one.

Single workspace

One workspace, a handful of callers, done properly and verified.

£497

Fixed price for the scope below, agreed in writing before anything starts.

  • 1 workspace
  • Up to 5 integrations
  • Up to 3 tokens
  • The inventory

    Every place your old key ended up, written down as a register you keep.

  • Token design

    One token per tool, scoped to the narrowest thing that actually works.

  • The cutover

    One integration at a time, each tested against its real job, not a test call.

  • The old key revoked

    Before the deadline, while we are both watching — not at 03:00 on the day.

  • Thirty days of aftercare

    Your monthly jobs have not run yet. That is the point.

Tell me what you have

Multi-workspace / agency

Several workspaces, or work running inside clients’ workspaces.

£1,495

Fixed price for the scope below, agreed in writing before anything starts.

  • Up to 5 workspaces
  • Up to 20 integrations
  • Up to 15 tokens
  • Everything in single workspace

    Across every workspace in scope.

  • The leaver review

    Which integrations die when someone leaves, and which need a workspace API key instead of a personal token.

  • A credential register

    Handed over in writing — what exists, who owns it, where it lives, what it can reach.

  • Client comms templates

    If you have to tell your own clients why you need access to their workspace.

Tell me what you have

Estate

Above five workspaces, or an enterprise workspace with token policies and SSO.

£2,495

Fixed price for the scope below, agreed in writing before anything starts.

  • A full working day
  • Scoped in writing first
  • No cap — we agree what fits
  • A working day, together

    This is the existing Dedicated Day, pointed at the migration.

  • Policy and plan work

    Workspace token policies, admin permissions, and whether a workspace API key needs a plan change.

  • Whatever else the day reaches

    If the migration finishes early, the rest of the day is yours.

Tell me what you have

Expedited

+50%

Booked after 8 October and delivered inside 48 hours.

Post-deadline rescue

£797

It is already broken. One workspace, 24-hour turnaround.

Credential hardening

+£297

The migration opens every credential store you own. While it is open: least privilege on every token, hardcoded secrets out of repos, an RLS spot-check.

If anything I migrated is still broken on 16 October, I fix it free.

The work is verifiable — either your integrations run or they do not — so this is an easy promise to make and an easy one to hold me to.

Not for you if

  • Nothing outside Base44 calls your apps — then you have nothing to do, and the free check will tell you so.
  • You want me to guess at scope and send an invoice later. The caps exist so neither of us does that.
  • You need it done inside the hour on 15 October. Book the rescue tier instead and be honest with me about what is already down.
  • You want the credentials handed to you in a spreadsheet. Tokens are shown once and go straight into a secret store.

How a done-for-you job runs

Six phases, in this order, every time.

  1. 01

    Inventory

    Every place a Base44 credential could live. A sweep of your code, then the dozen surfaces that are not in your repo. You get the register at the end whatever else happens.

  2. 02

    Token design

    Workspaces times tools. Scope and permission per token, defaulting to read-only and single-app. Anything that must outlive its creator gets flagged here, before any work is done.

  3. 03

    Storage

    Where each token lives, decided before any token is created — the value is shown once, and there is no second chance to copy it.

  4. 04

    Cutover

    One integration at a time. Whole header line replaced, test call, then the integration’s real job run once. Never batched. Your old key still works throughout, so nothing has to break.

  5. 05

    Revoke

    The old account key deleted before the deadline, while we are both watching. Anything missed surfaces in minutes instead of silently at 03:00.

  6. 06

    Aftercare, thirty days

    Your monthly and quarterly jobs have not fired yet. That is exactly why this is included rather than sold.

Reasonable questions

What actually changes?

Account API keys stop working on 15 October 2026. They are replaced by personal access tokens, created per workspace under Settings, then Secrets. The header changes from api_key: KEY to Authorization: Bearer TOKEN, and you replace the whole header line — a token sent under the old header name is rejected.

Can I just do it myself?

Often, yes, and the guide is written so you can. The part that catches people is not the header swap, it is finding every place the old key ended up, and deciding what to do about anything that has to keep working after the person who set it up moves on.

Why not wait until October?

Both credentials work in parallel until the deadline, so migrating early costs you nothing and risks nothing. Leaving it means doing discovery under time pressure, and discovery is the slow part. Work booked in the last week is also priced higher, because it displaces other work.

What if Base44 extends the deadline?

Then you have a documented inventory of everything that touches your Base44 apps, least-privilege tokens in place of one all-powerful key, and no cliff edge. That was worth doing anyway. If the date moves before I start your work, I will tell you rather than let you buy urgency you no longer need.

Do you need access to my account?

For the done-for-you tiers, yes — either as a member of the workspace or working alongside you on a call. Tokens are shown once, so they go straight into your own secret store; I do not keep a copy and I will not send you credentials by email.

What happens if something breaks after you have finished?

Thirty days of aftercare is included on every done-for-you tier, specifically because monthly jobs will not have run yet when the work finishes. And if anything I migrated is still broken on 16 October, I fix it free.

Everything on this page about Base44's platform was verified against their documentation and live API on 15 September 2026. Base44 is changing things during this transition — where this page and your screen disagree, trust your screen, and tell me so I can fix it.

Back to Base44