Skip to main content

API Keys

/keys (sidebar API Keys, page title Virtual keys) is where developers request virtual keys and operators run the lifecycle (reveal, rotate, block, revoke).

Concepts: Virtual keys.

Stat cards: Total keys, Active keys, Expiring soon (next 30 days), Total spend (all keys, lifetime) and Budget remaining.

When you have requests waiting for review, Pending requests lists them with budget, RPM, environment and team.

List​

  • Search by key alias, key ID, user, team or organization.
  • Status segments with counts: All, Active, Pending, Blocked, Revoked, Expired. Pending (pending reveal) and Revoked appear only when keys have that status.
  • Team filter. Reset clears the search and filters.

Table columns: Key (alias, masked ID, environment), Status, Owner (team, plus user or service account), Access (access group and model count), Spend / budget (spend and % of budget), Limits (TPM / RPM), Expires (marked "soon" within 30 days), Last active. Show 10, 25 or 50 rows per page.

Click an alias to open key details. Row menu: View details, Reveal (pending reveal only), Rotate key, Copy key ID, Block key / Unblock key, Revoke key.

Bulk actions​

Tick rows (the header checkbox selects the current page) to show the bulk bar:

  • Export downloads the selected keys as CSV: alias, ID, status, environment, team, organization, user, access group, models, spend, budget, limits, expiry, last request, requests and tokens.
  • Block blocks the selected active keys you can manage. Other selected keys are skipped.
  • Revoke revokes the selected keys that are not already revoked or expired. Type the key alias (one key) or revoke N keys to confirm.

Keys the action fails on are listed in an error message.

Key details​

The drawer shows the alias, status, environment and masked key ID (with copy). It has two tabs.

Details

  • Key details: team, organization, user (or service account owner), application, environment, created, last active, expiry
  • Access: the access group (or custom model list) and every model in it
  • Effective policy: each enabled guardrail policy that applies, marked attached to this key or inherited from a team, access group or organization, with its steps in order and Open policy →. No policy attached means requests are not content-filtered.
  • Limits: tokens per minute, requests per minute, budget (with reset period) and budget tier

Usage

  • Spend for the budget period, % used, amount left (or over budget) and reset date
  • Usage totals (all time): Requests, Tokens, Avg latency, Error rate
  • Requests per day for the last 30 days
  • Spend by model for the last 30 days (top five)
  • Open in FinOps Analytics opens FinOps Analytics filtered to this key for 30 days

The drawer footer offers Rotate key, Reveal (pending reveal) or Copy key ID, Block key / Unblock key and Revoke key, depending on status and your role. After a rotation the new secret is shown once in the drawer.

Request a key​

Request key opens Request an API key (also at /keys/request):

FieldNotes
Key ownershipYou (personal key) or Service account (team-owned; requires a team)
Key nameAlias, min 3 characters
Team / ApplicationTeam is optional for personal keys. Application (optional) lists the chosen team's applications
Models / access groupRequired; shows up to eight of the group's models
Policy (optional)Default None — inherit from org / team. The hint lists the team, org and access group policies the key would inherit
EnvironmentDevelopment, Staging, Production
PurposeRequired, min 8 characters; approvers see it
Budget tier (optional)Picking a tier fills in budget, duration, RPM and TPM. Custom limits below keeps your own values
BudgetLabel follows the duration (Monthly budget, Weekly budget, Daily budget); default $50 monthly
Budget durationMonthly, Weekly, Daily
Expiry90 days (default), 30 days, 180 days or Never
RPM / TPMRPM limit default 100; TPM limit (optional)

Submit request creates a KeyRequest in PENDING. Reviewers work on Approvals.

Reveal​

After approval the key is PENDING_REVEAL. Open it with Reveal (row menu or drawer):

  • Plaintext zea-… is minted once
  • Copy key and Copy base URL
  • Tick I've saved this key somewhere safe (enabled after you copy the key), then Continue to keys or Back to dashboard
  • Status becomes ACTIVE

The reveal page also has copy-paste examples. Pick an API operation and a Model, choose curl, Python, Node or Environment variables, then Copy. For chat completions with a chat model, Send test request sends one tiny chat request through the gateway, billed to this key. Other operations link to the API reference page.

Rotate, block, revoke​

  • Rotate (ACTIVE or BLOCKED): new secret, same settings; old secret dies immediately
  • Block / unblock: team or platform admin; gateway rejects blocked keys with 403 key_blocked
  • Revoke: permanent; 401 key_revoked

Who sees which keys​

  • Platform admin: all keys
  • Everyone else: own keys + keys on reviewable teams + keys they requested
  • For everyone, selecting an organization in the org switcher narrows the list to that organization's team keys; your personal keys without a team stay visible