List your API keys (metadata only — never the raw keys)
List every developer key on the authenticated account, including revoked ones — a non-null `revoked_at` marks a key as dead. Metadata only. Raw key values are stored hashed and are never returned by any endpoint; `key_prefix` is provided so you can match a row against a key you already hold. Unmetered.
Authorization
BearerAuth Your API key, sent as Authorization: Bearer wm_.... Keys are wm_ followed by 40 hex characters. Create one with POST /register (free, no auth) or POST /keys.
In: header
Response Body
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/keys"{ "keys": [ { "created_at": "2019-08-24T14:15:22Z", "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "name": "string", "revoked_at": "2019-08-24T14:15:22Z", "scopes": [ "string" ] } ]}Self-register for a free, extract-only API key (no auth)
Mint a free API key from an email address. **Public — no existing key required.** This is the zero-friction entry point: an agent can go from nothing to a working key in one call. The key returned is scoped to `extract` only and carries the free plan's allowance. Broader scopes are created with `POST /keys` once you're authenticated. The raw key is shown **once, in this response** — it is stored hashed and cannot be retrieved again. Rate-limited per IP; a 429 carries `Retry-After`.
Create a new scoped API key
Create an additional API key on the authenticated account, with its own name, scopes and compliance policy. Scopes narrow what a key may do — issue a key scoped to `extract` for an agent that should never be able to start a crawl. A key can only grant scopes the calling key already holds. The raw key is returned **once, in this response**, and is stored hashed; there is no way to read it back. Unmetered.