Skip to main content
Requires the admin action. See Authentication for scoping.

List keys

Returns all non-revoked keys for the organization.
Note: the response includes prefix (the first 8 chars of the key) but never the full secret. The full secret is only available at creation time.

Create a key

string
required
Human-facing label. Min 1, max 80 chars.
string
default:"agent"
One of agent, application, admin.
string[]
required
Array of actions (see Authentication → Actions). Min 1 entry.
string[]
default:"null"
Whitelist of provider IDs. null = no restriction.

Response

The secret field is returned only on creation. Repo stores a SHA-256 hash and cannot recover the secret. If you lose it, revoke the key and create a new one.

Tier limits

Each plan caps the number of active API keys: Hitting the cap returns 403 agent_limit_reached. Upgrade in the console to add more.

Revoke a key

Sets revoked_at on the row; future requests using the key get 401 Invalid API key immediately (no cache). Repo refuses to revoke the key currently authenticating the request — you can’t lock yourself out by accident. Use a different admin key to revoke this one.