Skip to content

Dev API Keys ​

API keys are project-scoped developer credentials. They let automation and server-side tools access project resources without an interactive hosted login, making them suitable for local development, CI pipelines, and backend environments.

API keys authenticate project public-state operations plus the /v1/api-key/info key-metadata endpoint. Everything else (projects, user state, API key management, hosted auth settings, account, and billing) requires a developer login from sky login.

Key properties:

  • Scoped to a single project
  • The full key value is shown only once at creation time - copy it immediately and store it securely
  • The plaintext key cannot be retrieved again after creation; only its prefix is shown afterwards
  • Keys can be revoked at any time; revocation is immediate and permanent
  • A lost key cannot be recovered - revoke it and create a new one. Keys can be rotated at any time from the console or with sky project keys

Managing API Keys ​

Console ​

Keys are created, viewed, and revoked from the project settings in the console.

CLI ​

Use sky project keys to create, list, and revoke project keys from the terminal. The onboarding wizard may create a key for Node.js or curl snippets when you choose that option.

Using an API Key ​

Use API keys only from trusted automation or backend code. Browser SDK auth uses hosted login and SkyState bearer tokens.

The key value looks like sky_.... Send it as Authorization: ApiKey <sky_...> for direct HTTP calls. Never commit it to source control - use an environment variable or secrets manager.

The metadata endpoint for the currently authenticated API key is:

text
GET /v1/api-key/info

Authentication is Authorization: ApiKey <sky_...> only; the standard per-credential rate limit applies (see Rate Limiting).

A 200 response is a JSON object with exactly these fields:

FieldTypeMeaning
projectNamestringName of the project the key belongs to
slugstringProject slug
accountIdstringAccount that owns the project
keyNamestringName given to the key at creation
keyPrefixstringKey prefix shown in the console and CLI
createdAtstring (ISO 8601 UTC timestamp)When the key was created
expiresAtalways nullAPI keys do not expire
lastUsedAtstring (ISO 8601 UTC timestamp) or nullnull until the key has been used; updated shortly after each authenticated request

The endpoint returns 401 with an empty body when the Authorization header is missing, carries a bearer token instead of an API key, or carries a key that is unknown, revoked, or whose project no longer exists.