API keys and secrets
Create and revoke keys per environment, store provider keys and credentials in the vault, and see where each secret is used.
API keys
Keys belong to the environment in the top bar. + New key:
- Name: for your own reference.
- Kind: Publishable (
kl_pub), safe to ship in the app, can only start sessions and chat; or Secret (kl_sec), server side only, can send notifications and read agents. - Scopes (secret keys): shown for future enforcement; today a secret key can call every secret-key endpoint.
The full key is shown once in a modal, with a ready-to-paste Flutter snippet for publishable keys. Afterwards only the prefix and last four characters are visible. Revoke stops the key immediately; create the replacement first and roll it out.
Secrets
Provider keys, tool credentials, the HS256 secret for end-user JWTs, and push service accounts. Names are lowercase snake_case (anthropic_key, acme_api). Values are encrypted on save with per-organisation envelope encryption and never displayed again, not even once; the list shows the last four characters and Used by (agents, tools, end-user auth, push).
- Rotate replaces the value under the same name; everything referencing it picks up the new value on the next call.
- Delete is refused while a tool, agent model or setting still references the secret.
Where secrets are referenced: Agent → Model → Your API key; Tool → Auth → Secret; Settings → End-user auth → Secret; Triggers → Push delivery.