> ## Documentation Index
> Fetch the complete documentation index at: https://docs.switchagents.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs moved from docs.flintai.dev to docs.switchagents.ai. Use docs.switchagents.ai for every link and request.
> To search these docs from an AI tool, connect the MCP server at https://docs.switchagents.ai/mcp. The page index is at https://docs.switchagents.ai/llms.txt.

# API keys

> Create and manage the API keys that authenticate your Switch Trust integrations

API keys authenticate the tools that talk to Switch Trust on your behalf, such as the CLI
scanner, your CI/CD pipelines, and the SDK. Each key carries a role, so it can do only what
that role allows.

To open this page, select the **Settings** icon <svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth={2} strokeLinecap="round" strokeLinejoin="round" style={{ display: "inline", verticalAlign: "text-bottom", margin: 0 }} aria-label="Settings"><path d="M20 7h-9" /><path d="M14 17H5" /><circle cx="17" cy="17" r="3" /><circle cx="7" cy="7" r="3" /></svg> in Switch Trust, then under **Admin** select **API keys**.

<Note>
  Reaching this page needs the **Editor** role or higher. A **Viewer** can't create or see
  API keys.
</Note>

## The keys list

The **My keys** view shows the keys you created. Use **Search keys** to filter it by name,
and the **Columns** control to show or hide any of the columns below, so you only see what you
need.

An **Admin** or **Org Admin** also gets an **All org keys** view, which shows every key in the
organization. With any other role, you see only your own keys, and there's no view to switch
to. Search is offered in **My keys** only.

Each key has these columns:

* **Name** is the label you gave the key when you created it.
* **Owner** is the member who created it. This column appears in **All org keys**. It's left
  out of **My keys**, since every key there is yours.
* **Key** is a masked preview of the value. The full value is shown only once, when you
  create the key.
* **Role** is the role the key acts with.
* **Status** shows whether the key is **Active**, when it's due to expire (for example,
  **Expires today** or **Expires in 5 days**), or **Expired**.
* **Created** is when the key was created.
* **Expires** is when the key lapses, or **Never** for a key with no expiration.

## Create a key

<Steps>
  <Step title="Open the create dialog">
    Select **Create key**.
  </Step>

  <Step title="Name the key and set its role">
    Enter a **Name** that says where the key is used, such as "Production Scanner". Choose the
    **Role** the key acts with, which sets what it's allowed to do. You can scope a key to any
    role up to your own, and it defaults to your role.
  </Step>

  <Step title="Set an expiration">
    Choose an **Expiration**. You can pick a preset (1 day, 7 days, 30 days, 90 days, or
    1 year) or set a custom number of days up to 365.
  </Step>

  <Step title="Create and copy the token">
    Select **Create key**. Switch Trust shows the full token once, with a **Show** or **Hide**
    control and the option to copy it.
  </Step>
</Steps>

<Warning>
  Copy the token as soon as it's shown. You won't be able to see it again, and there's no way
  to recover it. If you lose it, revoke the key and create a new one.
</Warning>

Set the token as your `FLINTAI_API_KEY` in the SDK, or as the secret your scanner or CI/CD
integration expects. See [SDK configuration](/switch-trust/sdk/python/configuration) for
where the key goes.

## Roles and key scoping

A key can act only within its role, so give each key the least access it needs. Because a
key's reach follows its owner's role, lowering someone's role revokes any of their keys
scoped above the new one. See [Roles and permissions](/switch-trust/admin/users#roles-and-permissions).

## Revoke a key

To turn off a key, select **Revoke** on its row and confirm. Revoking takes effect right
away and can't be undone, so anything still using the key stops working until you issue a
new one.

From the **All org keys** view, an **Admin** or **Org Admin** can also revoke keys other
members created, not just their own.
