> ## Documentation Index
> Fetch the complete documentation index at: https://magica-adi.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Bearer API keys for /api/v1. The full key is shown once.

Public routes do not use Clerk. A missing, malformed, or revoked key returns `401` with code `UNAUTHORIZED`.

```
Authorization: Bearer gxk_live_…
```

## Create a key

`POST /api/keys` requires the signed-in product session, not an API key.

<ParamField body="name" type="string" required>
  Label, 1–80 characters. Example: `ci`.
</ParamField>

```json theme={null}
{ "name": "ci" }
```

<ResponseField name="key" type="string">
  Full secret, prefix `gxk_live_`. Returned only on create.
</ResponseField>

<ResponseField name="id" type="string">
  Use this id to revoke the key.
</ResponseField>

<ResponseField name="prefix" type="string">
  First characters of the key. This is all that list returns.
</ResponseField>

## List and revoke

`GET /api/keys` returns active keys for the signed-in user: `id`, `name`, `prefix`, `lastUsedAt`, `createdAt`. It never returns `key`.

`DELETE /api/keys/{keyId}` revokes the key. Later public calls with that secret return `401`.

<Warning>
  Treat `gxk_live_…` like a password. If you lose it, revoke the key and create another. The API cannot show it again.
</Warning>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.