REST API
API Keys
On this page
Keys are scoped to exactly one workspace. The secret is shown once, at creation.
Create an API key
HTTP
POST /v1/workspaces/{ws_id}/keys
Auth: any credential · Role: dev
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
ws_id | string (UUID) | ✅ | Workspace ID — UUID, not slug |
Request body — KeyCreateBody
| Field | Type | Required | Description |
|---|---|---|---|
name | string | ✅ | Human label, e.g. ci-pipeline |
env | string | ✅ | live or test. The secret is shaped {kind}_{env}_{token}. |
kind | string | ✅ | opx (header auth), dr (bearer auth), or cck (Claude Code telemetry key) |
Response 200 — not schema-modelled
JSON
{
"key_id": "k_01J8XYZ...",
"name": "ci-pipeline",
"env": "live",
"kind": "opx",
"secret": "opx_live_xxxxxxxxxxxxxxxxxxxx",
"prefix": "opx_live_xxxx",
"created_at": "2026-09-01T14:23:05Z"
}
secretappears in this response and nowhere else, ever. Store it in your secret manager immediately. If lost, revoke the key and mint a new one.
Examples
key = evigauge.post(f"/v1/workspaces/{ws_id}/keys", json={
"name": "ci-pipeline",
"env": "live",
"kind": "opx",
})
# Capture the secret NOW — it is never returned again.
save_to_secret_manager(key["secret"])
print("key_id:", key["key_id"], "prefix:", key["prefix"])
const key = await evigauge.post(`/v1/workspaces/${wsId}/keys`, {
name: "ci-pipeline",
env: "live",
kind: "opx",
});
// Capture the secret NOW — it is never returned again.
await saveToSecretManager(key.secret);
console.log("key_id:", key.key_id, "prefix:", key.prefix);
List API keys
HTTP
GET /v1/workspaces/{ws_id}/keys
Returns key metadata and prefixes. Never returns secrets.
Auth: any credential · Role: dev
Examples
for k in evigauge.get(f"/v1/workspaces/{ws_id}/keys"):
print(f"{k['name']:20} {k['prefix']:18} {k['created_at']}")
const keys = await evigauge.get(`/v1/workspaces/${wsId}/keys`);
keys.forEach((k: any) =>
console.log(`${k.name.padEnd(20)} ${k.prefix.padEnd(18)} ${k.created_at}`));
Revoke an API key
HTTP
DELETE /v1/workspaces/{ws_id}/keys/{key_id}
Revocation is immediate and irreversible. In-flight requests using the key
begin failing with 401 at once.
Auth: any credential · Role: dev — but revoking a key you do not own
additionally requires admin or owner.
Examples
evigauge.delete(f"/v1/workspaces/{ws_id}/keys/{key_id}")
await evigauge.del(`/v1/workspaces/${wsId}/keys/${keyId}`);
Zero-downtime rotation:
Python
# 1. Mint the replacement.
new = evigauge.post(f"/v1/workspaces/{ws_id}/keys",
json={"name": "ci-pipeline-v2", "env": "live", "kind": "opx"})
# 2. Deploy new["secret"] everywhere and confirm traffic is flowing on it.
# 3. Only then revoke the old key.
evigauge.delete(f"/v1/workspaces/{ws_id}/keys/{old_key_id}")