Docs/Guides/API keys

API keys

API keys let you authenticate scripts, CI pipelines, or backend services without a login/password flow. A key authenticates as the user who created it, with that user's current role in the organization — if their role changes or they're removed, the key's effective access changes with it.

Create a key

curl -X POST https://api.astrabase.app/api/v1/organizations/$ORG_ID/api-keys \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "CI deploy key"}'
{
  "id": "...",
  "name": "CI deploy key",
  "key_prefix": "edb_ab12cd34",
  "api_key": "edb_ab12cd34_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
}

api_key is returned exactly once — it isn't stored anywhere retrievable, so save it immediately (e.g. as a CI secret). Every later listing only shows the key_prefix, for identification.

Using a key

Send it the same way as a login token:

curl https://api.astrabase.app/api/v1/organizations \
  -H "Authorization: Bearer edb_ab12cd34_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"

With an SDK, pass it as the token directly:

const client = new PlatformClient(undefined, "edb_ab12cd34_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx");

Listing and revoking

curl https://api.astrabase.app/api/v1/organizations/$ORG_ID/api-keys -H "Authorization: Bearer $TOKEN"
curl -X DELETE https://api.astrabase.app/api/v1/organizations/$ORG_ID/api-keys/$API_KEY_ID -H "Authorization: Bearer $TOKEN"

A revoked key stops working immediately.