Skip to main content

Management Keys

List Management Keys

Returns management keys in the current workspace, ordered by creation time with the newest key first. The api_key and token_hash fields are never returned by this endpoint; only token_prefix is included.

Create a Management Key

Mints a new opaque management key (sk-orq-<key_id>-<secret>) in the workspace. The raw secret is returned ONCE in the response and is never retrievable afterwards. The stored record retains only token_prefix and a SHA-256 token_hash.

List Capabilities

Returns the management capability catalog: the set of workspace-admin permission domains that can be granted to a management key. Each entry includes the domain id, display name, group, and the read / write verb support. Drives the permissions UI in the dashboard.

Retrieve a Management Key

Retrieves the metadata for an existing management key by its unique identifier. The raw secret is never returned: only token_prefix, permission_mode, and lifecycle fields.

Delete a Management Key

Permanently deletes a management key. Cache entries are invalidated immediately so an in-flight token cannot ride out the TTL. The response body is empty on success.

Update a Management Key

Updates mutable fields of a management key: display name, status (active / disabled / revoked), permission mode and access map, and expiry. Omitted fields keep their current values.