API Keys
/keys (sidebar API Keys, page title Virtual keys) is where developers request virtual keys and operators run the lifecycle (reveal, rotate, block, revoke).
Concepts: Virtual keys.
Header
- A refresh button reloads the page data.
- API reference opens the API reference page.
- Request key opens the request form (see Request a key).
Stat cards: Total keys, Active keys, Expiring soon (next 30 days), Total spend (all keys, lifetime) and Budget remaining.
When you have requests waiting for review, Pending requests lists them with budget, RPM, environment and team.
List
- Search by key alias, key ID, user, team or organization.
- Status segments with counts: All, Active, Pending, Blocked, Revoked, Expired. Pending (pending reveal) and Revoked appear only when keys have that status.
- Team filter. Reset clears the search and filters.
Table columns: Key (alias, masked ID, environment), Status, Owner (team, plus user or service account), Access (access group and model count), Spend / budget (spend and % of budget), Limits (TPM / RPM), Expires (marked "soon" within 30 days), Last active. Show 10, 25 or 50 rows per page.
Click an alias to open key details. Row menu: View details, Reveal (pending reveal only), Rotate key, Copy key ID, Block key / Unblock key, Revoke key.
Bulk actions
Tick rows (the header checkbox selects the current page) to show the bulk bar:
- Export downloads the selected keys as CSV: alias, ID, status, environment, team, organization, user, access group, models, spend, budget, limits, expiry, last request, requests and tokens.
- Block blocks the selected active keys you can manage. Other selected keys are skipped.
- Revoke revokes the selected keys that are not already revoked or expired. Type the key alias (one key) or
revoke N keysto confirm.
Keys the action fails on are listed in an error message.
Key details
The drawer shows the alias, status, environment and masked key ID (with copy). It has two tabs.
Details
- Key details: team, organization, user (or service account owner), application, environment, created, last active, expiry
- Access: the access group (or custom model list) and every model in it
- Effective policy: each enabled guardrail policy that applies, marked attached to this key or inherited from a team, access group or organization, with its steps in order and Open policy →. No policy attached means requests are not content-filtered.
- Limits: tokens per minute, requests per minute, budget (with reset period) and budget tier
Usage
- Spend for the budget period, % used, amount left (or over budget) and reset date
- Usage totals (all time): Requests, Tokens, Avg latency, Error rate
- Requests per day for the last 30 days
- Spend by model for the last 30 days (top five)
- Open in FinOps Analytics opens FinOps Analytics filtered to this key for 30 days
The drawer footer offers Rotate key, Reveal (pending reveal) or Copy key ID, Block key / Unblock key and Revoke key, depending on status and your role. After a rotation the new secret is shown once in the drawer.
Request a key
Request key opens Request an API key (also at /keys/request):
| Field | Notes |
|---|---|
| Key ownership | You (personal key) or Service account (team-owned; requires a team) |
| Key name | Alias, min 3 characters |
| Team / Application | Team is optional for personal keys. Application (optional) lists the chosen team's applications |
| Models / access group | Required; shows up to eight of the group's models |
| Policy (optional) | Default None — inherit from org / team. The hint lists the team, org and access group policies the key would inherit |
| Environment | Development, Staging, Production |
| Purpose | Required, min 8 characters; approvers see it |
| Budget tier (optional) | Picking a tier fills in budget, duration, RPM and TPM. Custom limits below keeps your own values |
| Budget | Label follows the duration (Monthly budget, Weekly budget, Daily budget); default $50 monthly |
| Budget duration | Monthly, Weekly, Daily |
| Expiry | 90 days (default), 30 days, 180 days or Never |
| RPM / TPM | RPM limit default 100; TPM limit (optional) |
Submit request creates a KeyRequest in PENDING. Reviewers work on Approvals.
Reveal
After approval the key is PENDING_REVEAL. Open it with Reveal (row menu or drawer):
- Plaintext
zea-…is minted once - Copy key and Copy base URL
- Tick I've saved this key somewhere safe (enabled after you copy the key), then Continue to keys or Back to dashboard
- Status becomes
ACTIVE
The reveal page also has copy-paste examples. Pick an API operation and a Model, choose curl, Python, Node or Environment variables, then Copy. For chat completions with a chat model, Send test request sends one tiny chat request through the gateway, billed to this key. Other operations link to the API reference page.
Rotate, block, revoke
- Rotate (
ACTIVEorBLOCKED): new secret, same settings; old secret dies immediately - Block / unblock: team or platform admin; gateway rejects blocked keys with
403key_blocked - Revoke: permanent;
401key_revoked
Who sees which keys
- Platform admin: all keys
- Everyone else: own keys + keys on reviewable teams + keys they requested
- For everyone, selecting an organization in the org switcher narrows the list to that organization's team keys; your personal keys without a team stay visible