DEVELOPER DOCS

REST API

API Keys

On this page

Keys are scoped to exactly one workspace. The secret is shown once, at creation.


Create an API key

HTTP
POST /v1/workspaces/{ws_id}/keys

Auth: any credential · Role: dev

Path parameters

NameTypeRequiredDescription
ws_idstring (UUID)✅Workspace ID — UUID, not slug

Request body — KeyCreateBody

FieldTypeRequiredDescription
namestring✅Human label, e.g. ci-pipeline
envstring✅live or test. The secret is shaped {kind}_{env}_{token}.
kindstring✅opx (header auth), dr (bearer auth), or cck (Claude Code telemetry key)

Response 200 — not schema-modelled

JSON
{
  "key_id": "k_01J8XYZ...",
  "name": "ci-pipeline",
  "env": "live",
  "kind": "opx",
  "secret": "opx_live_xxxxxxxxxxxxxxxxxxxx",
  "prefix": "opx_live_xxxx",
  "created_at": "2026-09-01T14:23:05Z"
}

secret appears in this response and nowhere else, ever. Store it in your secret manager immediately. If lost, revoke the key and mint a new one.

Examples

key = evigauge.post(f"/v1/workspaces/{ws_id}/keys", json={
    "name": "ci-pipeline",
    "env": "live",
    "kind": "opx",
})
# Capture the secret NOW — it is never returned again.
save_to_secret_manager(key["secret"])
print("key_id:", key["key_id"], "prefix:", key["prefix"])

List API keys

HTTP
GET /v1/workspaces/{ws_id}/keys

Returns key metadata and prefixes. Never returns secrets.

Auth: any credential · Role: dev

Examples

for k in evigauge.get(f"/v1/workspaces/{ws_id}/keys"):
    print(f"{k['name']:20} {k['prefix']:18} {k['created_at']}")

Revoke an API key

HTTP
DELETE /v1/workspaces/{ws_id}/keys/{key_id}

Revocation is immediate and irreversible. In-flight requests using the key begin failing with 401 at once.

Auth: any credential · Role: dev — but revoking a key you do not own additionally requires admin or owner.

Examples

evigauge.delete(f"/v1/workspaces/{ws_id}/keys/{key_id}")

Zero-downtime rotation:

Python
# 1. Mint the replacement.
new = evigauge.post(f"/v1/workspaces/{ws_id}/keys",
                    json={"name": "ci-pipeline-v2", "env": "live", "kind": "opx"})
# 2. Deploy new["secret"] everywhere and confirm traffic is flowing on it.
# 3. Only then revoke the old key.
evigauge.delete(f"/v1/workspaces/{ws_id}/keys/{old_key_id}")