Overview
API keys are durable, tenant-scoped credentials for programmatic access: the SDK, direct API calls, CI, and other automation. You present a key as a bearer token:ao_ prefix on the token. A value with that prefix is treated as a tenant API key; a Clerk JWT is treated as a dashboard session. Any other bearer value is rejected.
Token format and environments
A token has the shape:<env> is a short identifier for the deployment that minted the key (for example dev, stage, or prod). This is not something you choose per key: it comes from the conductor deployment’s own environment setting and is applied identically to every key that deployment issues. All keys issued by the same deployment share the same <env> segment.
The plaintext token is shown exactly once, at creation. Copy it then and store it in a secret manager: Orca cannot show it again. If it is lost, revoke the key and issue a new one.
Roles: a key inherits its creator
An API key inherits the role of whoever created it:owner, admin, member, or viewer. A key issued by an admin can reach admin-only surfaces; a key issued by a member cannot. Scope keys deliberately by having them issued under an account with the right role. See Roles & Access.
Expiry and revocation
- A key can be given an expiry; once past it, the key stops working.
- A key can be revoked at any time, which immediately invalidates it.
Managing keys
Manage keys from the dashboard under Settings, then API Keys, or through the API:
Minting, listing, and revoking keys all require at least the member role; a caller with no recognized tenant role is rejected. Visibility is also role-scoped: a member can only list and revoke keys they personally created, while admin and owner can see and revoke every key in the tenant.
Using a key
Related
Manage API keys
Issue and revoke keys with the CLI.
Roles & Access
How a key inherits its creator’s role.
SDK overview
Authenticate the SDK with an ao_ key.