# API Keys

## List Api Keys

`client.apiKeys.list(APIKeyListParamsquery?, RequestOptionsoptions?): PaginatedCursor<APIKey>`

**get** `/api/v1/beta/api-keys`

List API keys.

Name a `project_id` to list every key on that project, which its members
share; naming one you cannot read is a 404. Omit it to list your own. A
project-scoped key sees only its own project either way.

### Parameters

- `query: APIKeyListParams`

  - `expand?: Array<string>`

  - `key_type?: "agent" | "user" | null`

    - `"agent"`

    - `"user"`

  - `name?: string | null`

  - `page_size?: number | null`

  - `page_token?: string | null`

  - `project_id?: string | null`

### Returns

- `APIKey`

  Schema for an API Key.

  - `id: string`

    Unique identifier

  - `redacted_api_key: string`

    The key with its middle masked, except on the create response, which returns the full secret once and never again.

  - `user_id: string`

  - `created_at?: string | null`

    Creation datetime

  - `expires_at?: string | null`

    When the API key expires. Null if the key never expires.

  - `key_type?: "agent" | "user"`

    - `"agent"`

    - `"user"`

  - `metadata?: Record<string, unknown> | null`

  - `name?: string | null`

  - `project_id?: string | null`

  - `role?: "admin" | "agent_viewer" | "viewer" | "viewer_v2" | null`

    Role capping what this key may do. Null if the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

  - `updated_at?: string | null`

    Update datetime

### Example

```typescript
import LlamaCloudAdmin from '@llamaindex/llama-cloud-admin';

const client = new LlamaCloudAdmin({
  apiKey: process.env['LLAMA_CLOUD_API_KEY'], // This is the default and can be omitted
});

// Automatically fetches more pages as needed.
for await (const apiKey of client.apiKeys.list()) {
  console.log(apiKey.id);
}
```

#### Response

```json
{
  "items": [
    {
      "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "redacted_api_key": "redacted_api_key",
      "user_id": "user_id",
      "created_at": "2019-12-27T18:11:19.117Z",
      "expires_at": "2019-12-27T18:11:19.117Z",
      "key_type": "agent",
      "metadata": {
        "foo": "bar"
      },
      "name": "name",
      "project_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
      "role": "admin",
      "updated_at": "2019-12-27T18:11:19.117Z"
    }
  ],
  "next_page_token": "next_page_token",
  "total_size": 0
}
```

## Create Api Key

`client.apiKeys.create(APIKeyCreateParamsbody, RequestOptionsoptions?): APIKey`

**post** `/api/v1/beta/api-keys`

Create an API key.

Scope it to a project with `project_id`, which requires read access to that
project; omit it for a key that reaches every project you can read. A
project-scoped or agent key cannot create an API key. The response carries
the secret in `redacted_api_key`, and only this once.

### Parameters

- `body: APIKeyCreateParams`

  - `expires_at?: string | null`

    When the API key should expire. If not set, the key never expires.

  - `key_type?: "agent" | "user"`

    - `"agent"`

    - `"user"`

  - `name?: string | null`

  - `project_id?: string | null`

    The project ID to associate with the API key.

  - `role?: "admin" | "agent_viewer" | "viewer" | "viewer_v2" | null`

    Role capping what this key may do. A key can only ever be narrower than the user who created it, never broader. If not set, the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

### Returns

- `APIKey`

  Schema for an API Key.

  - `id: string`

    Unique identifier

  - `redacted_api_key: string`

    The key with its middle masked, except on the create response, which returns the full secret once and never again.

  - `user_id: string`

  - `created_at?: string | null`

    Creation datetime

  - `expires_at?: string | null`

    When the API key expires. Null if the key never expires.

  - `key_type?: "agent" | "user"`

    - `"agent"`

    - `"user"`

  - `metadata?: Record<string, unknown> | null`

  - `name?: string | null`

  - `project_id?: string | null`

  - `role?: "admin" | "agent_viewer" | "viewer" | "viewer_v2" | null`

    Role capping what this key may do. Null if the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

  - `updated_at?: string | null`

    Update datetime

### Example

```typescript
import LlamaCloudAdmin from '@llamaindex/llama-cloud-admin';

const client = new LlamaCloudAdmin({
  apiKey: process.env['LLAMA_CLOUD_API_KEY'], // This is the default and can be omitted
});

const apiKey = await client.apiKeys.create();

console.log(apiKey.id);
```

#### Response

```json
{
  "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
  "redacted_api_key": "redacted_api_key",
  "user_id": "user_id",
  "created_at": "2019-12-27T18:11:19.117Z",
  "expires_at": "2019-12-27T18:11:19.117Z",
  "key_type": "agent",
  "metadata": {
    "foo": "bar"
  },
  "name": "name",
  "project_id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
  "role": "admin",
  "updated_at": "2019-12-27T18:11:19.117Z"
}
```

## Delete Api Key

`client.apiKeys.delete(stringapiKeyID, RequestOptionsoptions?): APIKeyDeleteResponse`

**delete** `/api/v1/beta/api-keys/{api_key_id}`

Revoke an API key.

Revoking a project key takes access away from everyone using it, so it needs
key-management permission on that project. Your own unscoped keys need only
that you own them. A project-scoped key revokes only within its own project,
unscoped keys included.

### Parameters

- `apiKeyID: string`

### Returns

- `APIKeyDeleteResponse`

  Confirmation that a resource was deleted.

  - `cache_ttl_seconds: number`

    Maximum seconds until cached information expires

  - `success: boolean`

    Whether the resource was deleted

### Example

```typescript
import LlamaCloudAdmin from '@llamaindex/llama-cloud-admin';

const client = new LlamaCloudAdmin({
  apiKey: process.env['LLAMA_CLOUD_API_KEY'], // This is the default and can be omitted
});

const apiKey = await client.apiKeys.delete('182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e');

console.log(apiKey.cache_ttl_seconds);
```

#### Response

```json
{
  "cache_ttl_seconds": 0,
  "success": true
}
```

## Domain Types

### API Key

- `APIKey`

  Schema for an API Key.

  - `id: string`

    Unique identifier

  - `redacted_api_key: string`

    The key with its middle masked, except on the create response, which returns the full secret once and never again.

  - `user_id: string`

  - `created_at?: string | null`

    Creation datetime

  - `expires_at?: string | null`

    When the API key expires. Null if the key never expires.

  - `key_type?: "agent" | "user"`

    - `"agent"`

    - `"user"`

  - `metadata?: Record<string, unknown> | null`

  - `name?: string | null`

  - `project_id?: string | null`

  - `role?: "admin" | "agent_viewer" | "viewer" | "viewer_v2" | null`

    Role capping what this key may do. Null if the key authorizes as its owner.

    - `"admin"`

    - `"agent_viewer"`

    - `"viewer"`

    - `"viewer_v2"`

  - `updated_at?: string | null`

    Update datetime

### API Key Delete Response

- `APIKeyDeleteResponse`

  Confirmation that a resource was deleted.

  - `cache_ttl_seconds: number`

    Maximum seconds until cached information expires

  - `success: boolean`

    Whether the resource was deleted
