Key
Key API
Methods
Section titled “Methods”- POSTList API keys — never the secrets.List API keys — never the secrets. Tenant · name · prefix · status · scopes · created · last used · expires. Admin keys see every tenant (optionally filtered) plus how many requests still authenticate through the legacy env blob; a tenant key sees only its own. Auth-required.
- POSTMint a new API key for a tenant.Mint a new API key for a tenant. Returns the raw key ONCE (only a sha256 is stored). Admin keys may issue for any tenant; a tenant key may issue only for its own tenant and never wider than itself (abilities/collections must be a subset). Auth-required.
- POSTRevoke a key immediately (takes effect within the 30s auth cache).Revoke a key immediately (takes effect within the 30s auth cache). Admin, or the key's own tenant. Revoking the key you are calling with needs confirmSelf:true. Auth-required.
- POSTRotate a key: mints a successor with the same tenant/name/scopes (raw key returned ONCE) and gives the old key an exp...Rotate a key: mints a successor with the same tenant/name/scopes (raw key returned ONCE) and gives the old key an expiry — default 24h overlap — so consumers can be moved without an outage. Admin, or the key's own tenant. Auth-required.
- POSTWhat can THIS key do — tenant, the abilities it may call (expanded), collections, sub-tenant flag, admin, and — once ...What can THIS key do — tenant, the abilities it may call (expanded), collections, sub-tenant flag, admin, and — once it resolves through the keys table — id/prefix/created/expires/last used. What an MCP host or a generated docs page renders from. Auth-required; no admin needed.