Developer guide / API keys

Treat keys like credentials

Perminister API keys are server-only machine credentials, separate from human browser sessions and consumer-app sessions.

Key lifecycle

Create and manage keys from the signed-in dashboard.

01

Create with a narrow scope

Choose product, project, or workspace scope, only the actions needed, and an expiration. The effective authorization is limited by the account's active grants too.

02

Copy the secret once

The dashboard returns a random bearer key in the creation response. Spaces stores only its SHA-256 verifier; refresh the page and the raw key is gone.

03

Rotate, expire, or revoke

Create a replacement with the same scope, then revoke the prior key. Expired and revoked keys fail authorization on the next check.