# API Keys

## List Api Keys

**get** `/api/v1/beta/api-keys`

List API keys.

Name a `project_id` to list every key on that project, which its members
share; naming one you cannot read is a 404. Omit it to list your own. A
project-scoped key sees only its own project either way.

### Query Parameters

- `expand: optional array of string`

- `key_type: optional "agent" or "user"`

  - `"agent"`

  - `"user"`

- `name: optional string`

- `page_size: optional number`

- `page_token: optional string`

- `project_id: optional string`

### Cookie Parameters

- `session: optional string`

### Returns

- `items: array of APIKey`

  The list of items.

  - `id: string`

    Unique identifier

  - `redacted_api_key: string`

    The key with its middle masked, except on the create response, which returns the full secret once and never again.

  - `user_id: string`

  - `created_at: optional string`

    Creation datetime

  - `expires_at: optional string`

    When the API key expires. Null if the key never expires.

  - `key_type: optional "agent" or "user"`

    - `"agent"`

    - `"user"`

  - `metadata: optional map[unknown]`

  - `name: optional string`

  - `project_id: optional string`

  - `role: optional "admin" or "agent_viewer" or "viewer" or "viewer_v2"`

    Role capping what this key may do. Null if the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

  - `updated_at: optional string`

    Update datetime

- `next_page_token: optional string`

  A token, which can be sent as page_token to retrieve the next page. If this field is omitted, there are no subsequent pages.

- `total_size: optional number`

  The total number of items available. This is only populated when specifically requested. The value may be an estimate and can be used for display purposes only.

### Example

```http
curl https://api.cloud.llamaindex.ai/api/v1/beta/api-keys \
    -H "Authorization: Bearer $LLAMA_CLOUD_API_KEY"
```

#### Response

```json
{
  "items": [
    {
      "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "redacted_api_key": "redacted_api_key",
      "user_id": "user_id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "key_type": "agent",
      "metadata": {
        "foo": "bar"
      },
      "name": "name",
      "project_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "role": "admin",
      "updated_at": "2019-12-27T18:11:19.117Z"
    }
  ],
  "next_page_token": "next_page_token",
  "total_size": 0
}
```

## Create Api Key

**post** `/api/v1/beta/api-keys`

Create an API key.

Scope it to a project with `project_id`, which requires read access to that
project; omit it for a key that reaches every project you can read. A
project-scoped or agent key cannot create an API key. The response carries
the secret in `redacted_api_key`, and only this once.

### Cookie Parameters

- `session: optional string`

### Body Parameters

- `expires_at: optional string`

  When the API key should expire. If not set, the key never expires.

- `key_type: optional "agent" or "user"`

  - `"agent"`

  - `"user"`

- `name: optional string`

- `project_id: optional string`

  The project ID to associate with the API key.

- `role: optional "admin" or "agent_viewer" or "viewer" or "viewer_v2"`

  Role capping what this key may do. A key can only ever be narrower than the user who created it, never broader. If not set, the key authorizes as its owner.

  - `"admin"`

  - `"agent_viewer"`

  - `"viewer"`

  - `"viewer_v2"`

### Returns

- `APIKey object { id, redacted_api_key, user_id, 8 more }`

  Schema for an API Key.

  - `id: string`

    Unique identifier

  - `redacted_api_key: string`

    The key with its middle masked, except on the create response, which returns the full secret once and never again.

  - `user_id: string`

  - `created_at: optional string`

    Creation datetime

  - `expires_at: optional string`

    When the API key expires. Null if the key never expires.

  - `key_type: optional "agent" or "user"`

    - `"agent"`

    - `"user"`

  - `metadata: optional map[unknown]`

  - `name: optional string`

  - `project_id: optional string`

  - `role: optional "admin" or "agent_viewer" or "viewer" or "viewer_v2"`

    Role capping what this key may do. Null if the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

  - `updated_at: optional string`

    Update datetime

### Example

```http
curl https://api.cloud.llamaindex.ai/api/v1/beta/api-keys \
    -H 'Content-Type: application/json' \
    -H "Authorization: Bearer $LLAMA_CLOUD_API_KEY" \
    -d '{}'
```

#### Response

```json
{
  "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
  "redacted_api_key": "redacted_api_key",
  "user_id": "user_id",
  "created_at": "2019-12-27T18:11:19.117Z",
  "expires_at": "2019-12-27T18:11:19.117Z",
  "key_type": "agent",
  "metadata": {
    "foo": "bar"
  },
  "name": "name",
  "project_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
  "role": "admin",
  "updated_at": "2019-12-27T18:11:19.117Z"
}
```

## Delete Api Key

**delete** `/api/v1/beta/api-keys/{api_key_id}`

Revoke an API key.

Revoking a project key takes access away from everyone using it, so it needs
key-management permission on that project. Your own unscoped keys need only
that you own them. A project-scoped key revokes only within its own project,
unscoped keys included.

### Path Parameters

- `api_key_id: string`

### Cookie Parameters

- `session: optional string`

### Returns

- `cache_ttl_seconds: number`

  Maximum seconds until cached information expires

- `success: boolean`

  Whether the resource was deleted

### Example

```http
curl https://api.cloud.llamaindex.ai/api/v1/beta/api-keys/$API_KEY_ID \
    -X DELETE \
    -H "Authorization: Bearer $LLAMA_CLOUD_API_KEY"
```

#### Response

```json
{
  "cache_ttl_seconds": 0,
  "success": true
}
```

## Domain Types

### API Key

- `APIKey object { id, redacted_api_key, user_id, 8 more }`

  Schema for an API Key.

  - `id: string`

    Unique identifier

  - `redacted_api_key: string`

    The key with its middle masked, except on the create response, which returns the full secret once and never again.

  - `user_id: string`

  - `created_at: optional string`

    Creation datetime

  - `expires_at: optional string`

    When the API key expires. Null if the key never expires.

  - `key_type: optional "agent" or "user"`

    - `"agent"`

    - `"user"`

  - `metadata: optional map[unknown]`

  - `name: optional string`

  - `project_id: optional string`

  - `role: optional "admin" or "agent_viewer" or "viewer" or "viewer_v2"`

    Role capping what this key may do. Null if the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

  - `updated_at: optional string`

    Update datetime

### API Key Delete Response

- `APIKeyDeleteResponse object { cache_ttl_seconds, success }`

  Confirmation that a resource was deleted.

  - `cache_ttl_seconds: number`

    Maximum seconds until cached information expires

  - `success: boolean`

    Whether the resource was deleted
