Authenticate with an API key
Create an API key and use it to call the management API from your own application.
An API key is a bearer token you create to call the management API from your own code. Use one when you build directly against the API: a dashboard that reads audit events, or a script that manages policies.
Create a key
Open Settings, go to the API keys tab, and choose Create API key. Give it:
- a name, so you can recognize it later,
- an expiry (30 days, 60 days, 90 days, 365 days, or never), and
- the permissions it needs.

A key can only do what you can
You can grant a key only the permissions you already hold. If you can't manage rate limits, no key you create can either.
Changing your own access later does not change an existing key's permissions. If your access grows or shrinks, an already-created key keeps what you gave it until you rotate or revoke it.
Base URL
Every request goes to your organization's own gateway host:
https://<org-slug>.aisecurity.services.<region>.connect.secureauth.com/api/v1Your organization's slug is the first label of that host. Your region is us, eu, or aus.
To read the exact value, open Settings, go to the API keys tab, and copy the API base URL field.
Use the key
Send the key as a bearer token in the Authorization header. No other header is required:
curl https://<org-slug>.aisecurity.services.<region>.connect.secureauth.com/api/v1/auth/permissions \
-H "Authorization: Bearer saai_api_..."Call GET /auth/permissions to see what a key can do: it returns the grants attached to the credential that called it.
Permissions
Grant a key only the permissions it needs. Each row below lists the endpoints that require the permission.
A key can hold manage_api_keys, which lets it create, rotate, and revoke keys. It still can't create a key with more permissions than it holds.
| Permission | Endpoints that require it |
|---|---|
view_agentsView agents. |
|
view_agent_instancesView running agent instances. |
|
manage_agent_instancesCreate, change, and remove agent instances. |
|
view_mcpsView connected MCP servers. |
|
manage_mcpsAdd, configure, and remove MCP servers. |
|
view_policiesView policy rules. |
|
manage_policiesCreate, change, and remove policy rules. |
|
view_data_protectionView data protection settings. |
|
manage_data_protectionChange data protection settings. |
|
view_rate_limitsView rate limit rules. |
|
manage_rate_limitsCreate, change, and delete rate limit rules. |
|
view_topologyView the topology of agents, MCP servers, and connections. |
|
view_auditView the audit log of tool calls. |
|
view_tool_analyticsView tool usage analytics. |
|
view_agent_analyticsView agent usage analytics. |
|
view_user_analyticsView per-user usage analytics. |
|
view_mcp_analyticsView MCP server usage analytics. |
|
view_policy_analyticsView policy enforcement analytics. |
|
view_llm_analyticsView LLM usage analytics: tokens, cost, sessions, and requests. |
|
view_anomaly_detectionView anomaly detection findings. |
|
manage_anomaly_detectionConfigure anomaly detection. |
|
view_usersView users in the organization. |
|
manage_usersDelete users and groups in the organization. |
|
manage_connectionsManage connections between agents and MCP servers. |
|
view_tagsView tags. |
|
manage_tagsCreate, change, and remove tags. |
|
manage_ingest_keysCreate and revoke telemetry ingest keys. |
|
manage_seat_pricingManage per-seat pricing configuration. |
|
view_webhooksView webhooks and their delivery history. |
|
manage_webhooksCreate, change, and remove webhooks. |
|
view_nhiView NHI sources. |
|
manage_nhiAdd, configure, and remove NHI sources. |
|
view_inferenceView inference connections and the models bound to them. |
|
manage_inferenceAdd, change, and remove inference connections and their bindings. |
|
report_device_observationsReport device observations from an enrolled device agent. | No public endpoint requires it. |
view_devicesView enrolled devices. | No public endpoint requires it. |
manage_devicesRevoke enrolled devices. | No public endpoint requires it. |
enroll_devicesIssue software statements that let a device enroll. | No public endpoint requires it. |
view_device_observationsRead raw device observations exactly as sensors reported them. | No public endpoint requires it. |
view_api_keysView API keys. |
|
manage_api_keysCreate, rotate, and revoke API keys. |
|
view_rolesView roles and who holds them. |
|
manage_rolesCreate, change, and delete roles, and assign them to users. |
|
view_notificationsReceive live notifications of changes. | No public endpoint requires it. |
Rotate, revoke, and expire
Rotating a key issues a new secret on the same key and invalidates the old one immediately. Its name, permissions, and expiry stay the same. Update the application with the new secret and nothing else changes.
Revoking a key is permanent and immediate: the key stops authenticating right away and can't be brought back. A revoked key stays listed, marked revoked, so you keep a record of it.
An expired key stops working the moment it expires, with no warning. Note the expiry when you create a key, or rotate it ahead of time if the application still needs it.
Keep a key safe
- The full key is shown only once, when you create or rotate it. Copy it immediately; the gateway can't show it to you again.
- Treat a key like a password: don't share it over chat or email, and don't paste it into a support ticket.
- Never commit a key to source control, even in a private repository.
- Create one key per application. If a single application's key leaks, you revoke just that key instead of rotating credentials shared with everything else.
Next steps
- Conventions: paging, sorting, and identifiers, which apply to every operation.
- Errors: what a rejected request tells you, including what a
401from a revoked key looks like.
API
The management API behind the Agent Authority console, generated from its OpenAPI description. Base URL, credential, stability, and the conventions that apply to every operation.
Conventions
Paging, sorting, search, identifiers, and timestamps in the Agent Authority management API. The conventions shared across operations, documented once.
