Skip to main content
An API key lets your own code call your agents. It does one thing: invoke. A key cannot create, change, deploy or delete anything, so a leaked key can call your agents but cannot take over your organization.

Create a key

1

Open API keys

In the dashboard, open API keys and click Create key.
2

Name it and choose what it can call

  • Name: what uses it, for example Production backend. At most 60 characters.
  • Scope: All agents in the organization, or one agent.
  • Expires: optional. Leave it empty and the key works until you revoke it. A date means the key stops working at the end of that day, in your time zone.
Click Create key.
3

Copy the key

The key is shown once. Copy it now: Onecortex keeps only a hash of it, so nobody, including Onecortex, can show it to you again. If you lose it, create another.
Terminal

Use a key

Send it as a bearer token on every call:
See the invoke API. A key that is missing, unknown, revoked or expired is refused with 401 and one message for every case, A valid Onecortex API key is required., so the response never tells anyone which keys exist. A key scoped to one agent, used against another, gets 404 That agent does not exist.

Scope a key to one agent

A key for one agent is the safer default for anything that calls only that agent. If it leaks, only that agent can be called with it. The Scope column on the API keys page shows which agent a key is for, or All agents.

Revoke a key

Open the menu at the end of the key’s row and choose Revoke. Any application using the key stops working within 30 seconds. Revoking cannot be undone. The key stays in the list, marked Revoked. To rotate a key without downtime: create the new key, deploy it to your application, then revoke the old one. Last used on the old key’s row tells you when it stops being used. It is updated in batches, so it can lag by up to 30 seconds.

Keep keys on the server

A key belongs in your server’s environment or secret store, never in a repository, a mobile app or a web page, where anyone who reads it can call your agent.

What you see on the page

Last modified on September 28, 2026