API Keys¶
Use API keys for programmatic access to SkillMeat's API without interactive browser sign-in. Keys are personal tokens tied to your user account and inherit your roles and permissions.
Overview¶
API keys enable: - CI/CD pipelines — automated artifact deployment and management - Local scripts — programmatic access from your development environment - Third-party integrations — webhooks and automation platforms - Tooling — custom CLIs and SDKs
Each key is hashed at rest, can be revoked instantly, and optionally expires after a set period.
Creating an API Key¶
Via Web UI¶
- Navigate to Settings → API Keys
- Click Create Key
- Enter a descriptive name (e.g., "CI Pipeline" or "Local Development")
- (Optional) Set an expiration date; default is 90 days
- Click Create
The full key is displayed once. Copy and store it securely — you cannot view it again.
Via CLI¶
Output:
Created API key: smk_live_abc12345_xxxxxxxxxxxxxxxxxxxxxxxxxxxx
Name: My Key Name
Expires: 2026-08-19
Store the key in an environment variable or .env file:
Using an API Key¶
Via X-API-Key Header¶
curl -H "X-API-Key: smk_live_abc12345_xxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
https://skillmeat.example.com/api/v1/artifacts
Via Authorization Bearer Token¶
curl -H "Authorization: Bearer smk_live_abc12345_xxxxxxxxxxxxxxxxxxxxxxxxxxxx" \
https://skillmeat.example.com/api/v1/artifacts
In Code¶
TypeScript/JavaScript:
const response = await fetch('https://skillmeat.example.com/api/v1/artifacts', {
headers: {
'X-API-Key': process.env.SKILLMEAT_API_KEY
}
});
Python:
import os
import requests
headers = {
'X-API-Key': os.environ.get('SKILLMEAT_API_KEY')
}
response = requests.get(
'https://skillmeat.example.com/api/v1/artifacts',
headers=headers
)
Listing Keys¶
Via Web UI¶
Navigate to Settings → API Keys to see all your keys, their creation dates, and last-used timestamps.
Via CLI¶
Output:
Name Created Expires Last Used
--- --- --- ---
CI Pipeline 2026-05-21 2026-08-19 2026-05-21
Local Dev 2026-04-15 2026-07-14 2026-05-20
Revoking a Key¶
Via Web UI¶
- Navigate to Settings → API Keys
- Find the key you want to revoke
- Click Revoke
- Confirm the action
Revocation is immediate — the key cannot be used in subsequent requests.
Via CLI¶
Key Format & Security¶
API keys follow the format:
Where:
- smk_ — SkillMeat key prefix
- {env} — live or test (environment suffix)
- {prefix8} — 8-character alphanumeric prefix for indexing
- {secret32} — 32-character secret, hashed at rest using Argon2id
Security practices: - Never commit keys to version control; use environment variables - Rotate keys periodically (e.g., quarterly for production systems) - Revoke keys immediately if exposed - Use separate keys for each environment or integration - Restrict key permissions where possible (future enhancement)
Expiration & Limits¶
Default Behavior¶
- Default TTL: 90 days
- Maximum TTL: 365 days
- Per-user key limit: 20 active keys
- Soft-delete grace period: Revoked keys are soft-deleted (queries exclude them); hard-deleted after 90 days
Renewal¶
When a key expires, it stops authenticating. Create a new key and update your environment variables or configuration:
# Create a new key with the same name
skillmeat auth api-key create "CI Pipeline" --expires-in-days 90
# Revoke the old key
skillmeat auth api-key revoke "CI Pipeline (old)"
Multi-Worker Caveat¶
When multiple workers or processes use the same API key simultaneously, last_used_at updates are debounced (coalesced) to reduce database contention:
- Debounce window: 60 seconds (configurable via
api_keys_debounce_seconds) - Behavior: The timestamp reflects the most recent request within the window, but intermediate requests are not individually logged
If you need precise per-request audit trails, use separate keys per worker or enable audit logging for your deployment.
Troubleshooting¶
"Invalid API key"
- Verify the full key is copied correctly (spaces, line breaks)
- Check the key hasn't expired
- Confirm the key hasn't been revoked
- Ensure the key is being passed via X-API-Key header or Authorization: Bearer token
"Missing API key"
- Add the key to the X-API-Key header or Authorization: Bearer header
- Ensure environment variables are set correctly
"Unauthorized" - Your API key is valid, but you lack permission for the requested operation - Verify your SkillMeat roles and scopes match the endpoint requirements - Contact your SkillMeat administrator
Next Steps¶
- Authentication Architecture — deep dive on auth providers
- API Reference — full endpoint documentation
- CLI Commands — full CLI command reference