Skip to main content
A key is arena_sk_ followed by 43 base64url characters (256 bits). It is read-only, belongs to one Google or Apple account, and acts on that real Arena account.

Create a key

Keys are managed with a person’s session, never with a key. Use either:
The plaintext token is returned once, at creation. Only a hash is stored; if you lose it, revoke it and create another. New keys get records:read, portfolio:read and markets:read unless you choose fewer. See scopes.

Limits

Rotate

Rotation creates a new key with the same label and scopes. The old key keeps working for graceSeconds (0–86,400; default 0 revokes it at once), so a deploy can switch without a gap. A rotating key does not count toward the 10-key cap.

Revoke

Revocation is immediate: the next request with that key gets 401 invalid_token. Revoking twice answers 404 key_not_found, meaning the key is already gone.

Key management endpoints

The website and CLI call these. They accept a session (browser cookie, same-origin JSON only, or a signed-in CLI’s session token as the bearer). An arena_sk_ key is refused with 401 session_required, so a leaked key cannot mint its own replacement. A guest session is refused with 403 guest_account.
Keep keys server-side. Keyed endpoints send no CORS headers: a key belongs in a server, CLI or agent runner, never in browser code. If a key is ever sent over plain HTTP, revoke it.