# API keys

API keys authenticate scripts, integrations and agents against the public REST
API and MCP. Each key belongs to one user and carries scopes of the form
`<domain>:<read|write|destroy>` plus `*:read`; a write scope includes read.

Operations: `api_keys.list`, `api_keys.get` and `api_keys.usage` read metadata
and request counts (never the secret). `api_keys.update` renames a key or
narrows its scopes. `api_keys.revoke` ends a key permanently.
`api_keys.create` and `api_keys.rotate` return the secret once.

Rules:
- Creating and rotating a key needs a Clerk session (the Adlass app); an API
  key cannot mint or rotate keys.
- Scopes can only be narrowed, never widened. Users, tenant and audit scopes
  need the admin role.
- A rotated key keeps its old secret valid for 24 hours.
- Never print or store a returned secret anywhere except where the user asked.
