MintedKey

  • A freshly minted API key, including its one-time secret.

    • actor
      Type: string | null
      required

      Audit label recorded when this token was delegated for a sub-agent, or null. Set via the actor field of POST /v1/token.

    • createdAt
      Type: string
      required

      ISO 8601 timestamp of when the key was created.

    • expiresAt
      Type: string | null
      required

      ISO 8601 timestamp when the key expires and stops authenticating, or null if it never expires.

    • id
      Type: string
      required

      Unique key identifier (prefixed key_). Use it to revoke the key.

    • keyPrefix
      Type: string
      required

      The non-secret prefix of the key, safe to display so you can tell keys apart. The full secret is only ever returned once, at creation.

    • lastUsedAt
      Type: string | null
      required

      ISO 8601 timestamp the key was last used to authenticate, or null if never.

    • name
      Type: string
      required

      Human-readable label for the key.

    • parentKeyId
      Type: string | null
      required

      For a delegated token (minted via POST /v1/token), the id of the key it was derived from; null for a root key. Revoking the parent invalidates this token.

    • revokedAt
      Type: string | null
      required

      ISO 8601 timestamp the key was revoked, or null if still active.

    • scopes
      Type: array string[] | null
      required

      The capabilities this key is limited to, as a list of scope tokens (e.g. submissions:read) plus optional form:<id> constraints. null means the key is unrestricted (full account access).

    • secret
      Type: string
      required

      The full API-key secret. Shown exactly once, at creation, it is stored only as a hash and cannot be retrieved again. Save it now and send it as Authorization: Bearer <secret>.