What kinds of API keys exist?
Agent keys authenticate as an agent; task keys dispatch work with capability scopes; paired CLI keys belong to one device. Secrets are shown once and every key can be revoked.
Agent API keys (ctx_) belong to one agent and act as that principal. Task API keys (tsk_) are organization-scoped, created by an administrator, and limited to the capabilities and agents you list, with an optional expiry. Paired CLI keys are minted per device when you approve a pairing. In every case the full secret is returned once at creation, and revoking a key takes effect immediately.
Written for developers, it and security. Last reviewed 2026-09-15.
Related questions
Still need an answer?
Tell us what you were looking for and we reply within one business day.
Contact the team →Running a security review?
Documents, controls, and the request form live in the Trust Center.
Open the Trust Center →