Skip to content

API keys

API keys are issued, listed and revoked from a signed-in console session: a key cannot manage credentials, because one that could mint more could outlive its own revocation. The one exception points the other way — a key may revoke itself.

1 endpoint under /api/v1/api-keys/self. What every call shares is on the REST overview, and what they are for — with the calls for every SDK, the CLI and MCP — on Errors, retries & limits → Authentication. * marks a required field.

Revoke the API key used for this request

DELETE /api/v1/api-keys/self

Accepts an Idempotency-Key

Revokes the key this request authenticated with and answers 204 with no body. Takes no id, so it cannot revoke any other key. Called by imagestep logout.

  • The key stops working at once on the instance that answered; another instance that has validated it recently may accept it for up to 30 seconds more. Stop using the key after this call rather than racing that window.
  • Not repeatable: a second call cannot authenticate and answers 401 — after your own revoke, that means it worked.
  • A signed-in session (Bearer) has no key behind it and gets 400 invalid_state; it revokes a key by id instead (DELETE /api/v1/api-keys/{keyId}, session only).

Returns 204 — no body

The calling key is revoked; from now on it answers 401

Errors

StatusCode and when
400

invalid_state — this request did not authenticate with an API key