MintedKey
A freshly minted API key, including its one-time
secret.- actorType: string | nullrequired
Audit label recorded when this token was delegated for a sub-agent, or
null. Set via theactorfield ofPOST /v1/token. - createdType: string
At requiredISO 8601 timestamp of when the key was created.
- expiresType: string | null
At requiredISO 8601 timestamp when the key expires and stops authenticating, or
nullif it never expires. - idType: stringrequired
Unique key identifier (prefixed
key_). Use it to revoke the key. - keyType: string
Prefix requiredThe non-secret prefix of the key, safe to display so you can tell keys apart. The full secret is only ever returned once, at creation.
- lastType: string | null
Used At requiredISO 8601 timestamp the key was last used to authenticate, or
nullif never. - nameType: stringrequired
Human-readable label for the key.
- parentType: string | null
Key Id requiredFor a delegated token (minted via
POST /v1/token), theidof the key it was derived from;nullfor a root key. Revoking the parent invalidates this token. - revokedType: string | null
At requiredISO 8601 timestamp the key was revoked, or
nullif still active. - scopesType: array string[] | nullrequired
The capabilities this key is limited to, as a list of scope tokens (e.g.
submissions:read) plus optionalform:<id>constraints.nullmeans the key is unrestricted (full account access). - secretType: stringrequired
The full API-key secret. Shown exactly once, at creation, it is stored only as a hash and cannot be retrieved again. Save it now and send it as
Authorization: Bearer <secret>.