API keys

Scopes, creation, rotation and revocation.

Raw Markdown for agents: api_keys.md. MCP: read_guide("api_keys").

API keys authenticate scripts, integrations and agents against the public REST API and MCP. Each key belongs to one user and carries scopes of the form <domain>:<read|write|destroy> plus *:read; a write scope includes read.

Operations: api_keys.list, api_keys.get and api_keys.usage read metadata and request counts (never the secret). api_keys.update renames a key or narrows its scopes. api_keys.revoke ends a key permanently. api_keys.create and api_keys.rotate return the secret once.

Rules:

  • Creating and rotating a key needs a Clerk session (the Adlass app); an API key cannot mint or rotate keys.
  • Scopes can only be narrowed, never widened. Users, tenant and audit scopes need the admin role.
  • A rotated key keeps its old secret valid for 24 hours.
  • Never print or store a returned secret anywhere except where the user asked.