API keys
Scopes, creation, rotation and revocation.
Raw Markdown for agents: api_keys.md. MCP: read_guide("api_keys").
API keys authenticate scripts, integrations and agents against the public REST
API and MCP. Each key belongs to one user and carries scopes of the form
<domain>:<read|write|destroy> plus *:read; a write scope includes read.
Operations: api_keys.list, api_keys.get and api_keys.usage read metadata
and request counts (never the secret). api_keys.update renames a key or
narrows its scopes. api_keys.revoke ends a key permanently.
api_keys.create and api_keys.rotate return the secret once.
Rules:
- Creating and rotating a key needs a Clerk session (the Adlass app); an API key cannot mint or rotate keys.
- Scopes can only be narrowed, never widened. Users, tenant and audit scopes need the admin role.
- A rotated key keeps its old secret valid for 24 hours.
- Never print or store a returned secret anywhere except where the user asked.