Skip to main content

Create a key

To create a key, you need one of these:
  • A browser session: boat login with no key, or the dashboard.
  • A token that is already admin-scoped.
The create endpoint is POST /api/v1/api-keys/scoped.
During a credential rollout, Boat can turn off key creation for a short time. GET /api/v1/api-keys reports this in catalog.scopedCreationEnabled. While creation is off, the create endpoint returns a typed 503.
For the actions and presets, read Scopes. Boat shows the secret one time only. In scripts, capture it like this:
You can also use the API Keys tab in the dashboard. It has expiry presets, action presets, a raw action picker, and sandbox and environment selectors.

Use the key

What a key cannot do

  • Rotate and revoke need a browser session.
  • Create needs a browser session or an admin-scoped token. A credential that can make more credentials defeats least privilege.
  • To approve an agent claim, you need a browser session. API keys cannot approve agent claims. This includes admin keys and legacy keys.
Use boat api-key create|rotate|revoke after a browser sign-in, or use the API Keys tab.

List

Every surface can list keys. This is the only key operation that every surface can do. Boat never returns the secrets. Each row shows:
  • The id, the name, the prefix and the last four characters
  • The scope and the expiry
  • The last use
  • The request total for the last 30 days
  • How many sandboxes and Agents the key created that still exist
Boat labels expired keys and keys that expire soon. Restricted API keys get an empty apiKeys list. Only a browser or CLI session, or an unrestricted account key, gets the account-wide list.
TypeScript
Python

See usage for one key

boat api-key usage <id> prints the 30-day request total and the count of live resources. These are the same numbers as in the list.
  • Add --verbose to see the split between sandboxes and Agents, and the list of created resources.
  • The matching API is GET /api-keys/{id}/usage.
  • Usage still works after you revoke the key, if you still have the id.
Revoke stops the secret. It does not delete the sandboxes or Agents that the key created.