Skip to content
Docs menu

keys

Scoped API keys for programmatic access (CLI / MCP / SDK)

3 operations · 5 schemas

GET /v1/keys

List my API keys

listApiKeys · scope session

Metadata only — key material is never returned after creation. Revoked keys stay listed with revoked_at set so audit history keeps resolving. Newest first.

Parameters

listApiKeys parameters
NameInTypeDescription
limitqueryinteger

default 20 · ≥ 1 · ≤ 100

Page size.

cursorquerystring

length ≤ 512

Opaque cursor from the previous page's next_cursor.

Responses

listApiKeys responses
StatusDescriptionBody
200

Page of API keys.

ApiKeyPage
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json

POST /v1/keys

Create an API key

createApiKey · scope session

Mints a scoped programmatic key. The plaintext key (lucen_sk_...) is returned once, in this response, and never again — only an argon2 hash is stored. Requested scopes must be a subset of what the caller can grant (read ⊂ write ⊂ train); the redundant lower scopes may be omitted since they are implied. daily_gpu_hour_quota, when set, caps the GPU hours this key may reserve on priced executors per 24 h, inside the account's own RUN_DAILY_GPU_HOUR_QUOTA (createRun).

Request body

application/json · required · ApiKeyCreate

createApiKey request body
FieldTypeDescription
namerequiredstring

length 1–128

scopesrequiredarray of ApiKeyScope

items 1–3

daily_gpu_hour_quotanumber | null

> 0 · ≤ 999999.99

Responses

createApiKey responses
StatusDescriptionBody
201

Key created; key is the only time the secret is shown.

ApiKeyCreated
401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
422

Request failed validation.

Problemapplication/problem+json

DELETE /v1/keys/{key_id}

Revoke an API key

revokeApiKey · scope session

Revocation takes effect on the next request and cannot be undone. The row is retained (audit rows point at it); it keeps appearing in GET /v1/keys with revoked_at set. Idempotent — revoking an already-revoked key is still 204.

Parameters

revokeApiKey parameters
NameInTypeDescription
key_idrequiredpathId

API key id (key_...).

Responses

revokeApiKey responses
StatusDescriptionBody
204

Key revoked.

401

Missing or invalid credentials.

Problemapplication/problem+json
403

Authenticated but not allowed (visibility, membership or scope).

Problemapplication/problem+json
404

Resource not found (or hidden from the caller).

Problemapplication/problem+json

Schemas (5)

The schemas these operations reach before any other tag’s do. A type that links elsewhere is rendered on that tag’s page.

ApiKeyPage

object

ApiKeyPage fields
FieldTypeDescription
itemsrequiredarray of ApiKey
next_cursorrequiredstring | null

ApiKeyCreate

object

ApiKeyCreate fields
FieldTypeDescription
namerequiredstring

length 1–128

scopesrequiredarray of ApiKeyScope

items 1–3

daily_gpu_hour_quotanumber | null

> 0 · ≤ 999999.99

ApiKeyCreated

object

A freshly minted key. key is the plaintext secret and is present only in this response — store it now; the server keeps an argon2 hash and cannot show it again.

ApiKeyCreated fields
FieldTypeDescription
idrequiredId
namerequiredstring

length 1–128

key_prefixrequiredstring

length ≤ 32

scopesrequiredarray of ApiKeyScope

items 1–3

daily_gpu_hour_quotanumber | null

> 0 · ≤ 999999.99

last_used_atstring (date-time) | null (date-time)
revoked_atstring (date-time) | null (date-time)
created_atrequiredstring (date-time)
keyrequiredstring

The plaintext key — lucen_sk_.... Shown once.

ApiKey

object

API key metadata. The secret itself is never returned here.

ApiKey fields
FieldTypeDescription
idrequiredId
namerequiredstring

length 1–128

Human label shown in the settings UI.

key_prefixrequiredstring

length ≤ 32

Display fragment of the key (lucen_sk_ + the first 8 characters of the secret) — enough to recognise a key, useless as a credential.

scopesrequiredarray of ApiKeyScope

items 1–3

Scopes as granted (implied lower scopes are not expanded).

daily_gpu_hour_quotanumber | null

> 0 · ≤ 999999.99

Per-key daily GPU-hour cap. Stored from M2, enforced from M7; null means the account default applies.

last_used_atstring (date-time) | null (date-time)

Last time this key authenticated a request.

revoked_atstring (date-time) | null (date-time)

Set once revoked; a revoked key authenticates nothing.

created_atrequiredstring (date-time)

ApiKeyScope

string

one of read · write · train

Granted scope. Hierarchical: write implies read, train implies write.