Create with a narrow scope
Choose product, project, or workspace scope, only the actions needed, and an expiration. The effective authorization is limited by the account's active grants too.
Developer guide / API keys
Perminister API keys are server-only machine credentials, separate from human browser sessions and consumer-app sessions.
Create and manage keys from the signed-in dashboard.
Choose product, project, or workspace scope, only the actions needed, and an expiration. The effective authorization is limited by the account's active grants too.
The dashboard returns a random bearer key in the creation response. Spaces stores only its SHA-256 verifier; refresh the page and the raw key is gone.
Create a replacement with the same scope, then revoke the prior key. Expired and revoked keys fail authorization on the next check.