Skip to main content

Overview

API keys are durable, tenant-scoped credentials for programmatic access: the SDK, direct API calls, CI, and other automation. You present a key as a bearer token:
Orca tells API keys apart from interactive dashboard sessions (which authenticate with Clerk) by the ao_ prefix on the token. A value with that prefix is treated as a tenant API key; a Clerk JWT is treated as a dashboard session. Any other bearer value is rejected.

Token format and environments

A token has the shape:
where <env> is a short identifier for the deployment that minted the key (for example dev, stage, or prod). This is not something you choose per key: it comes from the conductor deployment’s own environment setting and is applied identically to every key that deployment issues. All keys issued by the same deployment share the same <env> segment.
The plaintext token is shown exactly once, at creation. Copy it then and store it in a secret manager: Orca cannot show it again. If it is lost, revoke the key and issue a new one.

Roles: a key inherits its creator

An API key inherits the role of whoever created it: owner, admin, member, or viewer. A key issued by an admin can reach admin-only surfaces; a key issued by a member cannot. Scope keys deliberately by having them issued under an account with the right role. See Roles & Access.

Expiry and revocation

  • A key can be given an expiry; once past it, the key stops working.
  • A key can be revoked at any time, which immediately invalidates it.
Revoked or expired keys are rejected on every request.

Managing keys

Manage keys from the dashboard under Settings, then API Keys, or through the API: Minting, listing, and revoking keys all require at least the member role; a caller with no recognized tenant role is rejected. Visibility is also role-scoped: a member can only list and revoke keys they personally created, while admin and owner can see and revoke every key in the tenant.

Using a key

Never send X-Tenant-ID: Orca strips it server-side. The tenant is always derived from the API key itself.

Manage API keys

Issue and revoke keys with the CLI.

Roles & Access

How a key inherits its creator’s role.

SDK overview

Authenticate the SDK with an ao_ key.
Last modified on September 6, 2026