---
title: API keys
url: https://base_url.placeholder/docs/api/api-keys
group: Surfaces
---

# API keys

API keys are issued, listed and revoked from a signed-in console session: a key cannot manage credentials, because one that could mint more could outlive its own revocation. The one exception points the other way — a key may revoke itself.

1 endpoint under `/api/v1/api-keys/self`. What every call shares is on [the REST overview](https://base_url.placeholder/docs/api#conventions), and what they are for — with the calls for every SDK, the CLI and MCP — on [Errors, retries & limits → Authentication](https://base_url.placeholder/docs/errors#auth). `*` marks a required field.

- DELETE /api/v1/api-keys/self — Revoke the API key used for this request

## Revoke the API key used for this request

DELETE /api/v1/api-keys/self

Accepts an [`Idempotency-Key`](https://base_url.placeholder/docs/errors#idempotency)

Revokes the key this request authenticated with and answers `204` with no body. Takes no id, so it cannot revoke any other key. Called by `imagestep logout`.

- The key stops working at once on the instance that answered; another instance that has validated it recently may accept it for up to 30 seconds more. Stop using the key after this call rather than racing that window.
- Not repeatable: a second call cannot authenticate and answers `401` — after your own revoke, that means it worked.
- A signed-in session (`Bearer`) has no key behind it and gets `400 invalid_state`; it revokes a key by id instead (`DELETE /api/v1/api-keys/{keyId}`, session only).

### Returns `204` — no body

The calling key is revoked; from now on it answers `401`

### Errors

| Status | Code and when |
| --- | --- |
| 400 | `invalid_state` — this request did not authenticate with an API key |
