# Creating and Managing API Keys (2026-07-21)

> Create an API key in the Kintsugi app, store it safely, and rotate or revoke it later

Source: https://docs.trykintsugi.com/docs/2026-07-21/getting-started/creating-and-managing-api-keys

Every Tenanted API request to a data endpoint carries an API key in the Api-Key header. This page covers creating a key in the app, the one moment you can copy it, and how to manage keys after that, in the app or through the API Keys endpoints.

Create Your First Key

Four clicks in the Configuration page.

Store It Safely

The key is shown once and never again.

Make an Authenticated Request

Send your key and confirm it works.

API Reference

Every endpoint your key can reach.

## Before You Start

You need an account on the Kintsugi platform and access to an organization.

API keys need a paid plan that includes them. If the API Keys tab asks you to upgrade, the organization you are signed in to does not include them yet, so check which organization you are in before you start.

A key created in the app is scoped to one organization and acts on that organization, so a request made with it needs no organization header. You can hold several keys at once, which is what makes rotation possible without downtime.

## Create an API Key

Open the API Keys Tab

Sign in to the Kintsugi platform. If you do not have an account yet, sign up first.

Select Configuration in the left sidebar, below Tools.

Configuration sits at the bottom of the sidebar, above your name and the organization switcher.

Configuration opens on a row of tabs. Select API Keys.

Configuration tabs: API Keys sits between Users and Exemptions.

The tab lists every key belonging to the organization you are signed in to, with a search box, a link back to this documentation, and a New button. A new organization has none yet.

The API Keys tab before any key exists.

Create a New API Key

Click New. The New Organization API Key dialog opens, named for the scope the key will have.

Choose when the key should expire: Never, One Month, Six Month, or One Year.

Expiry is the only decision the dialog asks you to make.

Pick the shortest window that covers the work. An expiring key limits how long a leaked one is useful, and the expiry date is the reminder to rotate. One Month suits local development and spikes, One Year suits a production integration you will rotate on schedule, and Never is worth choosing only when something other than the calendar will retire the key.

Confirm to generate the key.

Copy and Secure Your API Key

This is the only time the key is visible. Copy it before you close the dialog. There is no way to reveal it again, so a key you did not copy has to be deleted and replaced.

Click the copy icon, or Manually copy API key to select the full value yourself.

Copy the key here, or lose it.

Paste it straight into wherever your application reads secrets from, before you do anything else.

Click Done.

Three habits worth keeping from the start:

## Create an API Key

Read the key from the environment, never from source. A key in a commit is a key in your history, and rewriting history is a worse afternoon than rotating a key.

Use a separate key per application and environment. Keys are independent, so one can be revoked without taking the others down with it.

Share through a password manager, not chat or email.

Viewing and Managing Your API Keys

The API Keys tab lists each key with its truncated value under KEY, plus its CREATED and EXPIRES dates. Only the truncated form is ever shown again. Use the search box to find a key, and the three-dot menu (⋮) at the end of its row to delete it.

An existing key, and the delete action on its row menu.

Deleting a key takes effect immediately and cannot be undone. Anything still using it starts getting 401 unauthorized on the next call, so put the replacement in place first. See Error Handling for what an authentication failure looks like.

## Managing Keys Through the API

The Tenanted API exposes the same lifecycle as four endpoints. They manage credentials, so they do not accept an organization API key: they take the session token of a signed-in Owner or Admin, sent as Authorization: Bearer <token>, with Organization-Id naming the organization whose keys you are managing. An organization API key gets 401 unauthorized, and a request that sends both an Api-Key and a bearer token gets 400 multiple_credentials.

| Endpoint | What it does |
| --- | --- |
| GET /api-keys | Lists the organization's keys. active=false lists archived keys instead of current ones. Pages forward with limit (1 to 100, default 50) and cursor. |
| POST /api-keys | Creates a key and returns its secret token, once. |
| PATCH /api-keys/{api_key_id} | Changes a key's expiresAt, or removes the expiry with null. |
| DELETE /api-keys/{api_key_id} | Revokes a key. |

Creating a key takes one optional field. expiresAt is an RFC 3339 UTC timestamp ending in Z, and it has to be in the future; leave it out for a key that does not expire.

POST https://api.trykintsugi.com/api-keys

-H "Authorization: Bearer <token>"

-H "Organization-Id: orgn_12345"

-H "Api-Version: 2026-07-21"

-H "Content-Type: application/json"

{

"expiresAt": "2027-07-21T15:30:00Z"

}

A 201 Created returns the key's id and its token:

{
"id": "3f6c2b1e-8a4d-4c2e-9b1f-2d7e5a6c9f10",
"token": "tok_2mNpQr7Ls8f3k"
}

The token is returned here and never again. Listing keys returns their metadata ( id, scope, organizationId, createdAt, expiresAt), never the secret, so store the token before you do anything else.

A few rules worth knowing:

## Managing Keys Through the API

Updating sends expiresAt with a new future timestamp, or null to remove the expiry. An empty body returns 400 invalid_request, since it asks for no change. A successful update returns 204 No Content.

Revoking returns 204 No Content. A key you cannot revoke, including one that does not exist, returns 404 not_found.

A signed-in user without the Owner or Admin role gets 403 forbidden.

## Rotating a Key

Because an organization can hold several keys at once, rotation needs no downtime and no maintenance window:

Create the replacement

Generate a new key alongside the one you are retiring, in the app or with Create an API key.

Deploy it

Update the secret your application reads and roll it out.

Confirm the new key is live

Make a request and check it succeeds. Making an Authenticated Request is the quickest check.

Delete the old key

Only once nothing is using it. Deleting first is what turns a rotation into an outage.

Set expiry when you create the key and rotation stops being something you have to remember. The EXPIRES column is your schedule, and expiresAt on List API keys is the same date for your own tooling.

## Next Steps

Make an Authenticated Request

Send Api-Key, and learn when to add an organization selector.

Plan an Integration

Choose how you will integrate before you write code.

SDKs

Python, TypeScript, Java, PHP, and Ruby clients for the v1 API.

API Lab

Run each workflow interactively before you build it.

Error Handling

Status codes, error codes, and what a rejected key returns.

Kintsugi MCP

Give your AI coding assistant the v1 API and docs.

## Need Help?

Common Issues

Creating a Key

API Keys tab asks you to upgrade? API keys need a paid plan that includes them. Check the organization switcher in the lower left to confirm which organization you are in.

Permission denied? Through the API, managing keys takes the Owner or Admin role. Ask an Owner or Admin on your organization, in the Users tab.

Key not generating? Reload the Configuration page and try again. If it persists, contact support.

Using a Key

401 unauthorized? The key is wrong, expired, or deleted. Check the EXPIRES column, and check the header name is Api-Key.

404 not_found on every request? If you send Organization-Id, it has to name the organization the key was created in. Remove it, or correct it.

401 unauthorized on Users or API Keys endpoints? Those endpoints do not accept an organization API key. Send a signed-in user's session token instead. See Making an Authenticated Request.

Reading the response: Error Handling covers each status code and error code.

Lost or Leaked Keys

Lost the key? It cannot be recovered. Delete it and create another.

Key leaked? Delete it immediately, then create and deploy a replacement. Deleting is instant.

Committed a key to git? Delete the key first, then clean the history. Revoking is what actually stops it being used.

Which key is which? Match the truncated value in the KEY column against the start of the key your application holds.

Get Support

Email Support

Reach our support team at success@trykintsugi.com.

Phone Support

Call +1 (415) 840-8847.

Live Chat

Chat with us in real time.

Help Center

Product, billing, and filing guides, outside the developer docs.

API Reference

Every Tenanted endpoint, generated from the spec.

Developer Community Coming soon

## Need Help?

Connect with other developers building on Kintsugi.

---

Index of every page: https://docs.trykintsugi.com/llms.txt
