Create a key
Choose New API key and configure:
KAOP displays the token at creation. It can also be revealed later from the API keys screen by you
or an administrator, and reveal events are recorded in the
audit log. Store the token in a secret manager and
avoid copying it into source code, build logs, or command history.
Choose the identity
For shared or long-running automation, prefer a service account. A personal key stops
authenticating when the member behind it is suspended.
Use a key
Send the token as a bearer token on each request:Key lifecycle
- Status shows whether a key is active, expired, or revoked.
- Last used helps identify keys that can be retired.
- Revoke permanently invalidates the key. Issue and deploy a replacement first if the caller must remain available.
- Revoking a key that created its own service account also disables that per-key account. Revoking a key for an existing service account or member does not disable the underlying identity.
- Disabling the identity behind a key prevents that key from authenticating. Restoring a managed service account restores its still-valid keys; a revoked key stays revoked.
Next steps
Service accounts
Create a durable identity for automation.
Roles & permissions
Control what the identity behind a key can do.
APIs
Explore the endpoints available to authenticated callers.
Audit log
Review key creation, reveal, and revocation events.