# API Keys

An API key is a long secret that identifies one workspace. You use it as a bearer token for the REST API, and you can also use it to connect an AI tool such as Claude Code to the hosted connector (see [Connect Your AI](/docs/ai/connect)).

A key gives full REST access to its workspace, so treat it like a password. Keys look like this:

```text
flo_sk_live_<32 hex characters>
```

## Create and revoke keys in the dashboard

Only workspace admins can see or manage keys. Go to `Settings > API keys`.

1. Create a key and give it a name (up to 100 characters). Use one key per integration so you can revoke them separately.
2. Copy the key when it appears. It is shown once and cannot be retrieved later. Flomailr stores only a hash.
3. To cut a key off, revoke it. A revoked key stops working immediately and stays in the list marked as revoked.

The list shows each key's name, its first 12 characters (`flo_sk_live_`), when it was last used, and whether it is revoked.

## Manage keys over the API

These routes use a key to manage the keys of the same workspace. Any valid key can call them.

### List keys

```text
GET /api/v1/keys
```

Query: `limit`, `after` (see [pagination](/docs/api/overview)).

Each item has `id`, `name`, `prefix`, `lastUsedAt`, `revokedAt` and `createdAt`. The key itself is never returned.

### Create a key

```text
POST /api/v1/keys
```

```json
{ "name": "CRM sync" }
```

`name` is required and at most 100 characters. The response is `201` and includes the key once:

```json
{
  "data": {
    "id": "clx...",
    "name": "CRM sync",
    "prefix": "flo_sk_live_",
    "createdAt": "2026-10-04T12:00:00.000Z",
    "key": "flo_sk_live_..."
  }
}
```

### Get a key

```text
GET /api/v1/keys/:id
```

Returns the same fields as the list. `404` if the id is not in your workspace.

### Revoke a key

```text
DELETE /api/v1/keys/:id
```

Returns `200` with `{ "data": { "id": "...", "revokedAt": "..." } }`. Revoking an already revoked key is not an error. A key can revoke itself, which ends its own access.

## Keys and the connector

When you connect an AI tool with an API key instead of signing in, the connector acts as that workspace and can use every tool except the workspace-switching ones. Actions the AI takes with a key are written to the activity log under `Settings > Activity`. See [Sending Safely with AI](/docs/ai/send-safely).
