What kinds of API keys exist?

Agent keys authenticate as an agent; task keys dispatch work with capability scopes; paired CLI keys belong to one device. Secrets are shown once and every key can be revoked.

Agent API keys (ctx_) belong to one agent and act as that principal. Task API keys (tsk_) are organization-scoped, created by an administrator, and limited to the capabilities and agents you list, with an optional expiry. Paired CLI keys are minted per device when you approve a pairing. In every case the full secret is returned once at creation, and revoking a key takes effect immediately.

Written for developers, it and security. Last reviewed 2026-09-15.

Still need an answer?

Tell us what you were looking for and we reply within one business day.

Contact the team →

Running a security review?

Documents, controls, and the request form live in the Trust Center.

Open the Trust Center →

Something to report?

Security findings go straight to the people who fix them.

security@context.ai