Skip to main content

API keys

An API key lets code act as a Delegate user — driving agents, running tasks, and reading results without a browser session.

Who can do what​

TaskUserAgent ownerAdmin
Create a key for themselves✅✅✅
List and revoke their own keys✅✅✅
Mint a key on behalf of another member——✅
List and revoke another member's keys——✅

Two different things live here, and it's worth not confusing them with the BYOK provider keys under Organization → API Keys. Those are your Anthropic or OpenAI keys, used to run models. The keys on this page are Delegate credentials used to call Delegate.

Your own keys​

Settings → API Keys.

  1. Create New Key, give it a name that says where it will be used.
  2. Copy it now. The key is shown once and never again — only a short prefix is stored, so we can show you which key is which without being able to reproduce it.
  3. Revoke it from the same list when it's no longer needed.

A key acts as you: it reaches exactly the agents you can reach, with the role you have. It doesn't expand your access and it doesn't survive it — if your role is reduced, so is the key's.

Keys minted by an admin​

An admin can mint a key for another member of the organization. This exists for provisioning: an integration that creates users needs to hand each one a working credential, and it can't drive a browser to do it.

Two things follow:

  • The key acts as that user, not as the admin. Anything done with it is attributed to them.
  • Minting is audited, as is revoking. An admin can also revoke every key a user holds at once, which is the right move when someone leaves.

Because minting hands over a credential that acts as another person, it's restricted to admins of that user's own organization.

Using a key​

Send it as the X-Api-Key header. See Provisioning customers and the Python SDK for the integration patterns, and Delegate as an MCP server for driving agents from an MCP client.

Looking after them​

  • One key per use. Separate keys per script or environment means revoking one doesn't break the others, and the list stays meaningful.
  • Name them for where they live, not for what they do — "ci-deploy-runner" beats "automation".
  • Revoke rather than rotate quietly. Revocation is immediate.
  • Never put a key in client-side code. A Delegate API key is a full-privilege credential for that user. To put an agent in front of the public, use a share link, which is designed to be published.