> ## Documentation Index
> Fetch the complete documentation index at: https://docs.arena-predictions.com/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys

> Create, rotate and revoke arena_sk_ keys.

A key is `arena_sk_` followed by 43 base64url characters (256 bits). It is read-only, belongs to one Google or Apple account, and acts on that real Arena account.

## Create a key

Keys are managed with a person's session, never with a key. Use either:

* **Website:** [Settings → API keys](https://arena-predictions.com/settings#api-keys).
* **CLI:** signed in with `arena login`:

```bash theme={null}
arena keys create --label "nightly job" --save ./arena.key
ARENA_API_KEY_FILE=./arena.key arena keys check
```

The plaintext token is returned once, at creation. Only a hash is stored; if you lose it, revoke it and create another. New keys get `records:read`, `portfolio:read` and `markets:read` unless you choose fewer. See [scopes](/authentication#scopes).

## Limits

| Limit | Value |
| - | - |
| Active keys per account | 10 (`409 key_limit_reached`) |
| Keys created per 24 hours, rotations included | 20 (`429 key_creation_limited`) |
| Expiry | Optional, 1–365 days. `arena keys` defaults to 90 days. |

## Rotate

Rotation creates a new key with the same label and scopes. The old key keeps working for `graceSeconds` (0–86,400; default 0 revokes it at once), so a deploy can switch without a gap. A rotating key does not count toward the 10-key cap.

```bash theme={null}
arena keys rotate arena_sk_4Fq1XyZ --grace 10m --save ./arena.new.key
```

## Revoke

Revocation is immediate: the next request with that key gets `401 invalid_token`. Revoking twice answers `404 key_not_found`, meaning the key is already gone.

## Key management endpoints

The website and CLI call these. They accept a session (browser cookie, same-origin JSON only, or a signed-in CLI's session token as the bearer). An `arena_sk_` key is refused with `401 session_required`, so a leaked key cannot mint its own replacement. A guest session is refused with `403 guest_account`.

| Method | Path | |
| - | - | - |
| `GET` | [`/api_keys`](/api-reference/api-keys/list-api-keys) | List keys, newest first. Not paginated. |
| `POST` | [`/api_keys`](/api-reference/api-keys/create-api-key) | Create. Not idempotent. |
| `POST` | [`/api_keys/{id}/rotate`](/api-reference/api-keys/rotate-api-key) | Rotate with a grace period. |
| `DELETE` | [`/api_keys/{id}`](/api-reference/api-keys/revoke-api-key) | Revoke. |

<Warning>
  Keep keys server-side. Keyed endpoints send no CORS headers: a key belongs in a server, CLI or agent runner, never in browser code. If a key is ever sent over plain HTTP, revoke it.
</Warning>
