# API Keys

## List Api Keys

`api_keys.list(APIKeyListParams**kwargs)  -> SyncPaginatedCursor[APIKey]`

**get** `/api/v1/beta/api-keys`

List API keys.

Name a `project_id` to list every key on that project, which its members
share; naming one you cannot read is a 404. Omit it to list your own. A
project-scoped key sees only its own project either way.

### Parameters

- `expand: Optional[Sequence[str]]`

- `key_type: Optional[Literal["agent", "user"]]`

  - `"agent"`

  - `"user"`

- `name: Optional[str]`

- `page_size: Optional[int]`

- `page_token: Optional[str]`

- `project_id: Optional[str]`

### Returns

- `class APIKey: …`

  Schema for an API Key.

  - `id: str`

    Unique identifier

  - `redacted_api_key: str`

    The key with its middle masked, except on the create response, which returns the full secret once and never again.

  - `user_id: str`

  - `created_at: Optional[datetime]`

    Creation datetime

  - `expires_at: Optional[datetime]`

    When the API key expires. Null if the key never expires.

  - `key_type: Optional[Literal["agent", "user"]]`

    - `"agent"`

    - `"user"`

  - `metadata: Optional[Dict[str, object]]`

  - `name: Optional[str]`

  - `project_id: Optional[str]`

  - `role: Optional[Literal["admin", "agent_viewer", "viewer", "viewer_v2"]]`

    Role capping what this key may do. Null if the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

  - `updated_at: Optional[datetime]`

    Update datetime

### Example

```python
import os
from llama_cloud_admin import LlamaCloudAdmin

client = LlamaCloudAdmin(
    api_key=os.environ.get("LLAMA_CLOUD_API_KEY"),  # This is the default and can be omitted
)
page = client.api_keys.list()
page = page.items[0]
print(page.id)
```

#### Response

```json
{
  "items": [
    {
      "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "redacted_api_key": "redacted_api_key",
      "user_id": "user_id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "key_type": "agent",
      "metadata": {
        "foo": "bar"
      },
      "name": "name",
      "project_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "role": "admin",
      "updated_at": "2019-12-27T18:11:19.117Z"
    }
  ],
  "next_page_token": "next_page_token",
  "total_size": 0
}
```

## Create Api Key

`api_keys.create(APIKeyCreateParams**kwargs)  -> APIKey`

**post** `/api/v1/beta/api-keys`

Create an API key.

Scope it to a project with `project_id`, which requires read access to that
project; omit it for a key that reaches every project you can read. A
project-scoped or agent key cannot create an API key. The response carries
the secret in `redacted_api_key`, and only this once.

### Parameters

- `expires_at: Optional[Union[str, datetime, null]]`

  When the API key should expire. If not set, the key never expires.

- `key_type: Optional[Literal["agent", "user"]]`

  - `"agent"`

  - `"user"`

- `name: Optional[str]`

- `project_id: Optional[str]`

  The project ID to associate with the API key.

- `role: Optional[Literal["admin", "agent_viewer", "viewer", "viewer_v2"]]`

  Role capping what this key may do. A key can only ever be narrower than the user who created it, never broader. If not set, the key authorizes as its owner.

  - `"admin"`

  - `"agent_viewer"`

  - `"viewer"`

  - `"viewer_v2"`

### Returns

- `class APIKey: …`

  Schema for an API Key.

  - `id: str`

    Unique identifier

  - `redacted_api_key: str`

    The key with its middle masked, except on the create response, which returns the full secret once and never again.

  - `user_id: str`

  - `created_at: Optional[datetime]`

    Creation datetime

  - `expires_at: Optional[datetime]`

    When the API key expires. Null if the key never expires.

  - `key_type: Optional[Literal["agent", "user"]]`

    - `"agent"`

    - `"user"`

  - `metadata: Optional[Dict[str, object]]`

  - `name: Optional[str]`

  - `project_id: Optional[str]`

  - `role: Optional[Literal["admin", "agent_viewer", "viewer", "viewer_v2"]]`

    Role capping what this key may do. Null if the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

  - `updated_at: Optional[datetime]`

    Update datetime

### Example

```python
import os
from llama_cloud_admin import LlamaCloudAdmin

client = LlamaCloudAdmin(
    api_key=os.environ.get("LLAMA_CLOUD_API_KEY"),  # This is the default and can be omitted
)
api_key = client.api_keys.create()
print(api_key.id)
```

#### Response

```json
{
  "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
  "redacted_api_key": "redacted_api_key",
  "user_id": "user_id",
  "created_at": "2019-12-27T18:11:19.117Z",
  "expires_at": "2019-12-27T18:11:19.117Z",
  "key_type": "agent",
  "metadata": {
    "foo": "bar"
  },
  "name": "name",
  "project_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
  "role": "admin",
  "updated_at": "2019-12-27T18:11:19.117Z"
}
```

## Delete Api Key

`api_keys.delete(strapi_key_id)  -> APIKeyDeleteResponse`

**delete** `/api/v1/beta/api-keys/{api_key_id}`

Revoke an API key.

Revoking a project key takes access away from everyone using it, so it needs
key-management permission on that project. Your own unscoped keys need only
that you own them. A project-scoped key revokes only within its own project,
unscoped keys included.

### Parameters

- `api_key_id: str`

### Returns

- `class APIKeyDeleteResponse: …`

  Confirmation that a resource was deleted.

  - `cache_ttl_seconds: int`

    Maximum seconds until cached information expires

  - `success: bool`

    Whether the resource was deleted

### Example

```python
import os
from llama_cloud_admin import LlamaCloudAdmin

client = LlamaCloudAdmin(
    api_key=os.environ.get("LLAMA_CLOUD_API_KEY"),  # This is the default and can be omitted
)
api_key = client.api_keys.delete(
    "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
)
print(api_key.cache_ttl_seconds)
```

#### Response

```json
{
  "cache_ttl_seconds": 0,
  "success": true
}
```

## Domain Types

### API Key

- `class APIKey: …`

  Schema for an API Key.

  - `id: str`

    Unique identifier

  - `redacted_api_key: str`

    The key with its middle masked, except on the create response, which returns the full secret once and never again.

  - `user_id: str`

  - `created_at: Optional[datetime]`

    Creation datetime

  - `expires_at: Optional[datetime]`

    When the API key expires. Null if the key never expires.

  - `key_type: Optional[Literal["agent", "user"]]`

    - `"agent"`

    - `"user"`

  - `metadata: Optional[Dict[str, object]]`

  - `name: Optional[str]`

  - `project_id: Optional[str]`

  - `role: Optional[Literal["admin", "agent_viewer", "viewer", "viewer_v2"]]`

    Role capping what this key may do. Null if the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

  - `updated_at: Optional[datetime]`

    Update datetime

### API Key Delete Response

- `class APIKeyDeleteResponse: …`

  Confirmation that a resource was deleted.

  - `cache_ttl_seconds: int`

    Maximum seconds until cached information expires

  - `success: bool`

    Whether the resource was deleted
