API keys
API keys are issued, listed and revoked from a signed-in console session: a key cannot manage credentials, because one that could mint more could outlive its own revocation. The one exception points the other way — a key may revoke itself.
1 endpoint under /api/v1/api-keys/self. What every call shares is on the REST overview, and what they are for — with the calls for every SDK, the CLI and MCP — on Errors, retries & limits → Authentication. * marks a required field.
Revoke the API key used for this request
DELETE /api/v1/api-keys/self
Accepts an Idempotency-Key
Revokes the key this request authenticated with and answers 204 with no body. Takes no id, so it cannot revoke any other key. Called by imagestep logout.
- The key stops working at once on the instance that answered; another instance that has validated it recently may accept it for up to 30 seconds more. Stop using the key after this call rather than racing that window.
- Not repeatable: a second call cannot authenticate and answers
401— after your own revoke, that means it worked. - A signed-in session (
Bearer) has no key behind it and gets400 invalid_state; it revokes a key by id instead (DELETE /api/v1/api-keys/{keyId}, session only).
Returns 204 — no body
The calling key is revoked; from now on it answers 401
Errors
| Status | Code and when |
|---|---|
| 400 |
|