# Platform API for Keys

> API keys are managed in the panel, not through the API, so a leaked key cannot make new keys.

Keys are managed in the panel. You create, roll and revoke keys in
**Panel › Developers › Keys**, signed in to Refabric; the panel's routes refuse a key with
`403 session_required`. A key that leaks can call the operations its scopes allow; key management
stays in the panel, so a leaked key cannot be used to make a new one.

## What you do where

| Action | Where |
|---|---|
| Create a key (every scope) | **Panel › Developers › Keys** — the secret is shown once |
| Roll a key, with a grace period of at most 604800 seconds | **Panel › Developers › Keys** |
| Revoke a key | **Panel › Developers › Keys** — immediate |
| See what a key did | **Panel › Developers › Request log**, or `GET /v1/account/requests?api_key_id=key_…` |
| See the jobs a key started | `GET /v1/jobs?api_key_id=key_…` |
| Send a key | `Authorization: Key <key>` on every call ([Authentication](https://docs.refabric.com/api-reference/platform/authentication)) |

The scopes a key can hold, and what each one allows, are on
[Get your API key](https://docs.refabric.com/setting-up/get-your-api-key#scopes).

## Operation and scope

Every operation's required scope is on its own page and in the OpenAPI document
(`x-refabric-scopes`). A key without that scope is answered `403 scope_missing`.

:::note
`api_key_id` (`key_…`) is a key's id, shown in the panel — never the secret. It is safe to log and
to send to support.
:::

## Related

::::cards
:::card{title="Get your API key" href="/setting-up/get-your-api-key"}
Create, test, roll and revoke keys, step by step.
:::
:::card{title="Security" href="/api-reference/platform/security#if-a-key-leaks"}
What to do when a key leaks.
:::
::::
