API Keys - Python SDK
client.keys manages API keys used to authenticate this SDK and other platform
clients. Revealed plaintext values are secrets and must never be logged.
Overview
Available Operations
| Method | Description |
|---|---|
list(owner_id=None) | List API keys visible to the caller; admin callers may filter by owner. |
create(body) | Create an API key. |
reveal(id) | Reveal a key's plaintext value when policy permits. |
update(id, body) | Update description, active state, or expiration. |
delete(id) | Delete an API key. |
list
List API keys visible to the caller; admin callers may filter by owner.
Request
Optional keyword-only owner_id.
Response
list[ApiKeyResponse].
create
Create an API key.
Request
ApikeyRequest; required keyValue, with optional description, isActive,
and expiresAt. The caller generates the key value.
Response
ApiKeyResponse; may include one-time plaintextKey.
reveal
Reveal a key's plaintext value when policy permits.
Request
String id required.
Response
str.
update
Update description, active state, or expiration.
Request
String id and ApikeyRequest required.
Response
Updated ApiKeyResponse.
delete
Delete an API key.
Request
String id required.
Response
bool.
Field Reference and Examples
ApikeyRequest supports id, keyValue, isActive, description,
expiresAt, and createdBy. The caller must generate and submit keyValue;
normal users should not set ownership fields. ApiKeyResponse contains id,
isActive, description, expiresAt, createdBy, userId, masked
keyValue, and possibly one-time plaintextKey.
The response id is numeric while the key-management path accepts a string;
convert it with str(...) before follow-up calls.
keys = client.keys.list()
created = client.keys.create({
"keyValue": "sk-created-by-caller",
"description": "automation key",
"isActive": True,
})
key_id = str(created["id"])
plaintext = created.get("plaintextKey") or client.keys.reveal(key_id)
updated = client.keys.update(key_id, {
"description": "renamed key",
"isActive": True,
})
deleted = client.keys.delete(key_id)
All methods use the shared authentication and typed error behavior described in Response Conventions and Retry and Security.