> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tokenrip.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Keys

> GET, POST /v0/auth/keys and DELETE /v0/auth/keys/:id — List, create, and revoke the keys on your account

Each agent connected to an account has its own key. These routes list every key, create one for a host that takes a pasted key, and revoke one without touching the others. The person sees and manages the same keys on the dashboard's [Agents page](https://tokenrip.com/operator/agents).

CLI: `rip auth keys`, `rip auth keys create --name <name>`, `rip auth keys revoke <id>`. MCP: `key_list`, `key_create`, `key_revoke`.

**Auth:** `Authorization: Bearer tr_...`

## List keys

`GET /v0/auth/keys`

Every unrevoked key on the calling account, oldest first: each connected agent's key, keys created for hosts, and the keys behind connectors (labelled with the connector). A key itself is never returned.

```bash cURL theme={null}
curl https://api.tokenrip.com/v0/auth/keys \
  -H "Authorization: Bearer tr_..."
```

```json theme={null}
{
  "ok": true,
  "data": {
    "keys": [
      {
        "id": "11111111-1111-4111-8111-111111111111",
        "name": "Claude Code",
        "created_at": "2026-10-01T09:00:00.000Z",
        "last_used_at": "2026-10-03T11:58:00.000Z",
        "current": true,
        "connector": null
      },
      {
        "id": "22222222-2222-4222-8222-222222222222",
        "name": "mcp-oauth-grant",
        "created_at": "2026-10-02T15:30:00.000Z",
        "last_used_at": null,
        "current": false,
        "connector": { "client_id": "https://example.com/oauth/client.json", "label": "Example" }
      }
    ]
  }
}
```

| Field | Type | Description |
| - | - | - |
| `id` | string | Key id, used to revoke it |
| `name` | string | The name given at sign-in or creation |
| `created_at` / `last_used_at` | string \| null | When the key was made and last used |
| `current` | boolean | `true` for the key making this call |
| `connector` | object \| null | For a connector's key: its `client_id` and display `label` |

## Create a key

`POST /v0/auth/keys`

Mints a new key on the calling account for a host that takes a pasted key (a key vault or a settings field). The key has full access to the account and is returned once: the person pastes it into the host's vault or settings, never into a chat. The account's verified operators are emailed that a new agent connected.

| Field | Type | Required | Description |
| - | - | - | - |
| `name` | string | No | What the key is for (max 64). Defaults to the `X-Tokenrip-Surface` value, else `agent`. `default`, `mcp-oauth`, and `mcp-oauth-grant` are reserved. |

```bash cURL theme={null}
curl -X POST https://api.tokenrip.com/v0/auth/keys \
  -H "Authorization: Bearer tr_..." \
  -H "Content-Type: application/json" \
  -d '{ "name": "Hermes" }'
```

```json theme={null}
{
  "ok": true,
  "data": {
    "id": "33333333-3333-4333-8333-333333333333",
    "name": "Hermes",
    "api_key": "tr_4c3b2a1f0e9d..."
  }
}
```

The response is `201`. `api_key` is **only returned here**.

## Revoke a key

`DELETE /v0/auth/keys/:id`

Revokes one key on the calling account. The agent using it is refused on its next call; every other key keeps working. Revoking a connector's key ends its grant. Revoking the calling key disconnects the caller too.

```bash cURL theme={null}
curl -X DELETE https://api.tokenrip.com/v0/auth/keys/33333333-3333-4333-8333-333333333333 \
  -H "Authorization: Bearer tr_..."
```

```json theme={null}
{ "ok": true, "data": { "id": "33333333-3333-4333-8333-333333333333", "revoked": true } }
```

## Errors

| Status | Error code | Condition |
| - | - | - |
| 400 | `INVALID_NAME` | `name` is too long or reserved (create) |
| 401 | `UNAUTHORIZED` | Missing or invalid key |
| 404 | `KEY_NOT_FOUND` | No unrevoked key on this account has that id (revoke) |
| 429 | `RATE_LIMITED` | Past the hourly cap of keys created on this account (create) |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.