Browse documentation
API keys
Authenticate API requests and control access with scopes.
View MarkdownAPI keys authenticate requests to Salambo API v1. Each key belongs to one workspace and has an explicit set of scopes.
export SALAMBO_API_KEY="sk_..."All API requests use bearer-token authentication:
Authorization: Bearer $SALAMBO_API_KEYKey format
Every Salambo API key is a live key that starts with sk_live_. There is no separate test mode: use a separate test agent or workspace when you want to exercise your integration without touching production agents.
The key prefix is stored for display and lookup. The full secret is hashed at rest and shown only once when the key is created or rotated.
Scopes
Scopes determine what the key can do.
| Scope | Use |
|---|---|
models:read | List available active agent models. |
run:read | Retrieve runs, turns, and retained events. |
run:write | Start, continue, steer, cancel, and delete runs. |
files:read | Read run files and file content. |
files:write | Upload input files. |
agents:read | List and inspect agents. |
agents:write | Create, update, archive, and run agents. |
env_vars:read | List environment variable metadata. |
env_vars:write | Create, update, and delete environment variables. |
env_vars:reveal | Reveal secret environment variable values. |
api_keys:manage | Create, rotate, and revoke API keys through the API. |
Scope rules
- A scope that changes or reveals a resource needs its read scope:
run:writeneedsrun:read,files:writeneedsfiles:read,agents:writeneedsagents:read, andenv_vars:writeorenv_vars:revealneedenv_vars:read. - A key must grant at least one scope, and each scope only once.
- Native Runs use
run:readandrun:write. The older pluralruns:readandruns:writescopes no longer exist.
Runtime-capable scopes
Salambo treats these scopes as runtime-capable:
run:writefiles:readfiles:write
Creating or rotating a key with any of those scopes checks runtime billing readiness for the workspace billing owner. Configuration-only scopes can still be used for setup flows that do not start or access runtime execution.
Last used timestamp
When a key successfully authenticates, Salambo updates its last_used_at timestamp on a best-effort basis. A recently used key can show a recent last-used time even if the request later fails a runtime readiness check.
Security practices
- Store API keys in environment variables or a secret manager.
- Do not commit secrets to source control.
- Use separate keys per environment and integration.
- Give each key only the scopes it needs.
- Revoke keys that are no longer used.
Continue with Create an API key for the complete workspace setup and verification flow.