Docs/Guides/API keys
API keys
API keys let you authenticate scripts, CI pipelines, or backend services without a login/password flow. A key authenticates as the user who created it, with that user's current role in the organization — if their role changes or they're removed, the key's effective access changes with it.
Create a key
curl -X POST https://api.astrabase.app/api/v1/organizations/$ORG_ID/api-keys \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{"name": "CI deploy key"}'
{
"id": "...",
"name": "CI deploy key",
"key_prefix": "edb_ab12cd34",
"api_key": "edb_ab12cd34_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
}
api_key is returned exactly once — it isn't stored anywhere retrievable,
so save it immediately (e.g. as a CI secret). Every later listing only shows
the key_prefix, for identification.
Using a key
Send it the same way as a login token:
curl https://api.astrabase.app/api/v1/organizations \
-H "Authorization: Bearer edb_ab12cd34_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
With an SDK, pass it as the token directly:
const client = new PlatformClient(undefined, "edb_ab12cd34_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx");
Listing and revoking
curl https://api.astrabase.app/api/v1/organizations/$ORG_ID/api-keys -H "Authorization: Bearer $TOKEN"
curl -X DELETE https://api.astrabase.app/api/v1/organizations/$ORG_ID/api-keys/$API_KEY_ID -H "Authorization: Bearer $TOKEN"
A revoked key stops working immediately.
Was this page helpful?