> ## Documentation Index
> Fetch the complete documentation index at: https://klef.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage API keys

Members can manage their own keys from **Settings > API keys**.

## Create a Key

<Steps>
  <Step title="Open API keys">
    Navigate to **Settings > API keys** and select **Create key**.

    <Frame>
      <img src="https://mintcdn.com/klef/M0QfE1SpDP4T0o0l/images/api-keys.png?fit=max&auto=format&n=M0QfE1SpDP4T0o0l&q=85&s=7550d602d25910bed124aa1501ad4143" alt="The API keys settings page" width="1261" height="485" data-path="images/api-keys.png" />
    </Frame>
  </Step>

  <Step title="Name and scope it">
    Give the key a name. Choose **Full access**, or **Custom scopes** to grant only the [permissions](/docs/reference/roles-and-permissions) it needs.

    <Note>
      Keys are maximally scoped to your permissions, so you cannot grant any permission you do not hold yourself. As such, **Full access** means your full permissions.
    </Note>
  </Step>

  <Step title="Set an expiry">
    Pick an expiration (30, 60, 90, 120, or 365 days, or no expiration). The default is 90 days.
  </Step>

  <Step title="Copy the secret">
    Select **Create key** and copy the secret. The secret is only shown once.
  </Step>
</Steps>

## Use a Key

When making API requests, pass your secret as a bearer token under the `Authorization` header and point the request to your workspace's subdomain (`acme` in the example below).

```bash theme={null}
curl https://acme.klef.ai/api/workers \
  -H "Authorization: Bearer klef_sk_..."
```

## Rotate a Key

Open the key's row menu, select **Rotate**, and copy the new secret. The key retains its name and scopes, but the old secret stops working immediately. Rotate whenever a secret has leaked, may have leaked, or was forgotten.

<Warning>
  Only rotate when you are able to deploy a replacement. Anything using the old secret will fail immediately until you give it the new one.
</Warning>

## Revoke a Key

Open the key's row menu and select **Revoke**. The key stops working immediately and anything using it can no longer authenticate.

<CardGroup cols={2}>
  <Card title="Roles and permissions" icon="shield-halved" href="/docs/reference/roles-and-permissions">
    The scopes a key can hold.
  </Card>

  <Card title="Manage members" icon="users" href="/docs/how-to/manage-members">
    Add teammates to the workspace.
  </Card>
</CardGroup>
