ApiKey

Metadata about an API key. The secret itself is never included here.

  • actor
    Type: string | null
    required

    Audit label recorded when this token was delegated for a sub-agent, or null. Set via the actor field of POST /v1/token.

  • createdAt
    Type: string
    required

    ISO 8601 timestamp of when the key was created.

  • expiresAt
    Type: string | null
    required

    ISO 8601 timestamp when the key expires and stops authenticating, or null if it never expires.

  • id
    Type: string
    required

    Unique key identifier (prefixed key_). Use it to revoke the key.

  • keyPrefix
    Type: string
    required

    The non-secret prefix of the key, safe to display so you can tell keys apart. The full secret is only ever returned once, at creation.

  • lastUsedAt
    Type: string | null
    required

    ISO 8601 timestamp the key was last used to authenticate, or null if never.

  • name
    Type: string
    required

    Human-readable label for the key.

  • parentKeyId
    Type: string | null
    required

    For a delegated token (minted via POST /v1/token), the id of the key it was derived from; null for a root key. Revoking the parent invalidates this token.

  • revokedAt
    Type: string | null
    required

    ISO 8601 timestamp the key was revoked, or null if still active.

  • scopes
    Type: array string[] | null
    required

    The capabilities this key is limited to, as a list of scope tokens (e.g. submissions:read) plus optional form:<id> constraints. null means the key is unrestricted (full account access).