Skip to main content
Public routes do not use Clerk. A missing, malformed, or revoked key returns 401 with code UNAUTHORIZED.

Create a key

POST /api/keys requires the signed-in product session, not an API key.
string
required
Label, 1–80 characters. Example: ci.
string
Full secret, prefix gxk_live_. Returned only on create.
string
Use this id to revoke the key.
string
First characters of the key. This is all that list returns.

List and revoke

GET /api/keys returns active keys for the signed-in user: id, name, prefix, lastUsedAt, createdAt. It never returns key. DELETE /api/keys/{keyId} revokes the key. Later public calls with that secret return 401.
Treat gxk_live_… like a password. If you lose it, revoke the key and create another. The API cannot show it again.