Skip to content
MouseMouse
Docs menu

API keys and scopes

What a read, write or train key can do, what only a signed-in person can do, and the rate limits.

Prompt for your AI

Read https://mousemouse.ai/docs/api-keys.md first. Tell me which API key scope I need for what I want to do, and nothing more. Ask me before anything that costs money or moves a robot.

An API key lets the CLI, a script or your own AI act as you. Each key has one scope, and the scopes nest: read is inside write, which is inside train. Give each key the least it needs.

Creating a key

Open API keys, name the key, choose its scope and press Create key. The page shows the key once. The hub keeps only a hash of it. Only a signed-in person can create or revoke a key, so a key that leaks cannot make another.

A key can also carry a daily GPU-hour limit on what it starts in Lucen cloud. Leave it empty for no limit.

What each scope can do

ScopeWhat a key with it can do
no keySearch public robots, policies and datasets. Read a dataset's episodes. Read the Coach's principles and lessons.
readAll of the above, plus everything the key's owner can see: private repos, training runs and sim tests.
writeAll of read, plus changing data: create repos, upload files, set a robot's card, import a run trained elsewhere. Connect a robot and ask to run a policy on it.
trainAll of write, plus what can cost money: start training runs and sim tests, and ask the Coach for a diagnosis.

What only a signed-in person can do

These need a person signed in to the hub in a browser. No API key of any scope can do them, and neither can an agent:

  • create or revoke an API key;
  • confirm a robot that claimed a pairing code;
  • approve or deny a request to run a policy on a robot;
  • stop a policy running on a robot;
  • override a fine-tune rule, with a written reason.

How approvals keep your robot safe explains why.

Where a key lives

  • The CLI stores it with lucen auth login, in a file only you can read.
  • Your own AI reads it from the MCP server's environment. No tool takes a key as an argument. Use the hub from your AI has the setup.
  • A script sends it as Authorization: Bearer lucen_sk_….

A robot never holds an API key. It pairs with a code and makes its own key.

Limits

  • 60 requests a minute without a key, per address.
  • 600 requests a minute per key or signed-in person.
  • The Coach has a daily allowance per account, shared by every key.

A private robot, policy, dataset or run answers "not found" to anyone who may not see it. So does one that does not exist.

The API reference lists the scope of every operation.