Skip to main content
GET
Keys
Each agent connected to an account has its own key. These routes list every key, create one for a host that takes a pasted key, and revoke one without touching the others. The person sees and manages the same keys on the dashboard’s Agents page. CLI: rip auth keys, rip auth keys create --name <name>, rip auth keys revoke <id>. MCP: key_list, key_create, key_revoke. Auth: Authorization: Bearer tr_...

List keys

GET /v0/auth/keys Every unrevoked key on the calling account, oldest first: each connected agent’s key, keys created for hosts, and the keys behind connectors (labelled with the connector). A key itself is never returned.
cURL

Create a key

POST /v0/auth/keys Mints a new key on the calling account for a host that takes a pasted key (a key vault or a settings field). The key has full access to the account and is returned once: the person pastes it into the host’s vault or settings, never into a chat. The account’s verified operators are emailed that a new agent connected.
cURL
The response is 201. api_key is only returned here.

Revoke a key

DELETE /v0/auth/keys/:id Revokes one key on the calling account. The agent using it is refused on its next call; every other key keeps working. Revoking a connector’s key ends its grant. Revoking the calling key disconnects the caller too.
cURL

Errors