Create a key
To create a key, you need one of these:- A browser session:
boat loginwith no key, or the dashboard. - A token that is already admin-scoped.
POST /api/v1/api-keys/scoped.
During a credential rollout, Boat can turn off key creation for a short time.
GET /api/v1/api-keys reports this in catalog.scopedCreationEnabled. While creation is off, the create endpoint returns a typed 503.
For the actions and presets, read Scopes.
Boat shows the secret one time only. In scripts, capture it like this:
Use the key
What a key cannot do
- Rotate and revoke need a browser session.
- Create needs a browser session or an admin-scoped token. A credential that can make more credentials defeats least privilege.
- To approve an agent claim, you need a browser session. API keys cannot approve agent claims. This includes admin keys and legacy keys.
boat api-key create|rotate|revoke after a browser sign-in, or use the API Keys tab.
List
Every surface can list keys. This is the only key operation that every surface can do. Boat never returns the secrets. Each row shows:- The id, the name, the prefix and the last four characters
- The scope and the expiry
- The last use
- The request total for the last 30 days
- How many sandboxes and Agents the key created that still exist
apiKeys list. Only a browser or CLI session, or an unrestricted account key, gets the account-wide list.
TypeScript
Python
See usage for one key
boat api-key usage <id> prints the 30-day request total and the count of live resources. These are the same numbers as in the list.
- Add
--verboseto see the split between sandboxes and Agents, and the list of created resources. - The matching API is
GET /api-keys/{id}/usage. - Usage still works after you revoke the key, if you still have the id.