Keys
curl --request GET \
--url https://api.example.com/v0/auth/keysimport requests
url = "https://api.example.com/v0/auth/keys"
response = requests.get(url)
print(response.text)const options = {method: 'GET'};
fetch('https://api.example.com/v0/auth/keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/v0/auth/keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/v0/auth/keys"
req, _ := http.NewRequest("GET", url, nil)
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.example.com/v0/auth/keys")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/v0/auth/keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
response = http.request(request)
puts response.read_bodyIdentity
Keys
GET, POST /v0/auth/keys and DELETE /v0/auth/keys/:id — List, create, and revoke the keys on your account
GET
/
v0
/
auth
/
keys
Keys
curl --request GET \
--url https://api.example.com/v0/auth/keysimport requests
url = "https://api.example.com/v0/auth/keys"
response = requests.get(url)
print(response.text)const options = {method: 'GET'};
fetch('https://api.example.com/v0/auth/keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/v0/auth/keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/v0/auth/keys"
req, _ := http.NewRequest("GET", url, nil)
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://api.example.com/v0/auth/keys")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/v0/auth/keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
response = http.request(request)
puts response.read_bodyEach agent connected to an account has its own key. These routes list every key, create one for a host that takes a pasted key, and revoke one without touching the others. The person sees and manages the same keys on the dashboard’s Agents page.
CLI:
The response is
rip auth keys, rip auth keys create --name <name>, rip auth keys revoke <id>. MCP: key_list, key_create, key_revoke.
Auth: Authorization: Bearer tr_...
List keys
GET /v0/auth/keys
Every unrevoked key on the calling account, oldest first: each connected agent’s key, keys created for hosts, and the keys behind connectors (labelled with the connector). A key itself is never returned.
cURL
curl https://api.tokenrip.com/v0/auth/keys \
-H "Authorization: Bearer tr_..."
{
"ok": true,
"data": {
"keys": [
{
"id": "11111111-1111-4111-8111-111111111111",
"name": "Claude Code",
"created_at": "2026-10-01T09:00:00.000Z",
"last_used_at": "2026-10-03T11:58:00.000Z",
"current": true,
"connector": null
},
{
"id": "22222222-2222-4222-8222-222222222222",
"name": "mcp-oauth-grant",
"created_at": "2026-10-02T15:30:00.000Z",
"last_used_at": null,
"current": false,
"connector": { "client_id": "https://example.com/oauth/client.json", "label": "Example" }
}
]
}
}
| Field | Type | Description |
|---|---|---|
id | string | Key id, used to revoke it |
name | string | The name given at sign-in or creation |
created_at / last_used_at | string | null | When the key was made and last used |
current | boolean | true for the key making this call |
connector | object | null | For a connector’s key: its client_id and display label |
Create a key
POST /v0/auth/keys
Mints a new key on the calling account for a host that takes a pasted key (a key vault or a settings field). The key has full access to the account and is returned once: the person pastes it into the host’s vault or settings, never into a chat. The account’s verified operators are emailed that a new agent connected.
| Field | Type | Required | Description |
|---|---|---|---|
name | string | No | What the key is for (max 64). Defaults to the X-Tokenrip-Surface value, else agent. default, mcp-oauth, and mcp-oauth-grant are reserved. |
cURL
curl -X POST https://api.tokenrip.com/v0/auth/keys \
-H "Authorization: Bearer tr_..." \
-H "Content-Type: application/json" \
-d '{ "name": "Hermes" }'
{
"ok": true,
"data": {
"id": "33333333-3333-4333-8333-333333333333",
"name": "Hermes",
"api_key": "tr_4c3b2a1f0e9d..."
}
}
201. api_key is only returned here.
Revoke a key
DELETE /v0/auth/keys/:id
Revokes one key on the calling account. The agent using it is refused on its next call; every other key keeps working. Revoking a connector’s key ends its grant. Revoking the calling key disconnects the caller too.
cURL
curl -X DELETE https://api.tokenrip.com/v0/auth/keys/33333333-3333-4333-8333-333333333333 \
-H "Authorization: Bearer tr_..."
{ "ok": true, "data": { "id": "33333333-3333-4333-8333-333333333333", "revoked": true } }
Errors
| Status | Error code | Condition |
|---|---|---|
| 400 | INVALID_NAME | name is too long or reserved (create) |
| 401 | UNAUTHORIZED | Missing or invalid key |
| 404 | KEY_NOT_FOUND | No unrevoked key on this account has that id (revoke) |
| 429 | RATE_LIMITED | Past the hourly cap of keys created on this account (create) |