For AI agents: this page is also available as Markdown at https://docs.refabric.com/api-reference/platform/keys.md, and the index of every page is https://docs.refabric.com/llms.txt.

Platform API

Platform API for Keys

API keys are managed in the panel, not through the API, so a leaked key cannot make new keys.

Keys are managed in the panel. You create, roll and revoke keys in Panel › Developers › Keys, signed in to Refabric; the panel's routes refuse a key with 403 session_required. A key that leaks can call the operations its scopes allow; key management stays in the panel, so a leaked key cannot be used to make a new one.

What you do where

ActionWhere
Create a key (every scope)Panel › Developers › Keys — the secret is shown once
Roll a key, with a grace period of at most 604800 secondsPanel › Developers › Keys
Revoke a keyPanel › Developers › Keys — immediate
See what a key didPanel › Developers › Request log, or GET /v1/account/requests?api_key_id=key_…
See the jobs a key startedGET /v1/jobs?api_key_id=key_…
Send a keyAuthorization: Key <key> on every call (Authentication)

The scopes a key can hold, and what each one allows, are on Get your API key.

Operation and scope

Every operation's required scope is on its own page and in the OpenAPI document (x-refabric-scopes). A key without that scope is answered 403 scope_missing.

api_key_id (key_…) is a key's id, shown in the panel — never the secret. It is safe to log and to send to support.