Dev API Keys
API keys are project-scoped developer credentials. They let automation and server-side tools access project resources without an interactive hosted login, making them suitable for local development, CI pipelines, and backend environments.
API keys authenticate project public-state operations plus the /v1/api-key/info key-metadata endpoint. Everything else (projects, user state, API key management, hosted auth settings, account, and billing) requires a developer login from sky login.
Key properties:
- Scoped to a single project
- The full key value is shown only once at creation time - copy it immediately and store it securely
- The plaintext key cannot be retrieved again after creation; only its prefix is shown afterwards
- Keys can be revoked at any time; revocation is immediate and permanent
- A lost key cannot be recovered - revoke it and create a new one. Keys can be rotated at any time from the console or with
sky project keys
Managing API Keys
Console
Keys are created, viewed, and revoked from the project settings in the console.
CLI
Use sky project keys to create, list, and revoke project keys from the terminal. The onboarding wizard may create a key for Node.js or curl snippets when you choose that option.
Using an API Key
Use API keys only from trusted automation or backend code. Browser SDK auth uses hosted login and SkyState bearer tokens.
The key value looks like sky_.... Send it as Authorization: ApiKey <sky_...> for direct HTTP calls. Never commit it to source control - use an environment variable or secrets manager.
The metadata endpoint for the currently authenticated API key is:
text
GET /v1/api-key/infoAuthentication is Authorization: ApiKey <sky_...> only; the standard per-credential rate limit applies (see Rate Limiting).
A 200 response is a JSON object with exactly these fields:
| Field | Type | Meaning |
|---|---|---|
projectName | string | Name of the project the key belongs to |
slug | string | Project slug |
accountId | string | Account that owns the project |
keyName | string | Name given to the key at creation |
keyPrefix | string | Key prefix shown in the console and CLI |
createdAt | string (ISO 8601 UTC timestamp) | When the key was created |
expiresAt | always null | API keys do not expire |
lastUsedAt | string (ISO 8601 UTC timestamp) or null | null until the key has been used; updated shortly after each authenticated request |
The endpoint returns 401 with an empty body when the Authorization header is missing, carries a bearer token instead of an API key, or carries a key that is unknown, revoked, or whose project no longer exists.