API keys

Creating keys for the SDK and CLI, what device keys are, and how to revoke access.

Find them in Settings → API Keys. There are two kinds, and most people never create one by hand.

Device keys

Created for you when you approve a machine during install. They carry a device name and device id, and they are what lets your terminal report runs.

You do not create these here. They appear here, and you can revoke them here.

Keys you create

For the SDK or CLI, or for a second tool you are wiring up yourself. Create key opens a dialog asking for three things:

  • Name. Required, so you can tell keys apart later.
  • Product. All products, ArmorClaude, ArmorCodex, or ArmorCopilot. Scoping a key to one product limits the blast radius if it leaks.
  • Expiration. Never, 30 days, 7 days, or 1 day.

The secret is shown exactly once, when the key is created. Copy it then. If you lose it, revoke the key and make a new one. There is no way to see it again.

If the dialog reports that the server did not return the secret, revoke that key and try again rather than assuming it works.

Revoking

Each row shows the key name, its type, its product, its status, the device if it has one, the key prefix, when it was created, and when it was last used, or that it has never been used.

Revoking takes two clicks, Revoke then Confirm revoke. Revoke a key when a laptop is lost, when you are done with an integration, or when a key has never been used and you cannot say why it exists.

What a key does not tell you

An active key means a key exists and has not been revoked. It does not mean a machine is currently connected or currently reporting. The Tools screen makes that distinction explicitly, pairing key status with whether a real evaluated session was actually seen. Scopes exist in the data model but there is no scope picker in the console today, so keys are not scope-restricted from this screen.

On this page