agk_*) is a credential bound to one Agent; its secret starts with ak_ntl_. A request made with it acts as that agent. Give it to an agent runtime; it carries the same verified binding as an agent-scoped MCP OAuth grant.
An API key is the party-wide counterpart: it acts as the party and cannot act as an agent. An agent key is scoped to its agent, nothing else.
Issuing
Issue one withPOST /agent-keys. Agent keys can only be issued, rotated, or revoked from a user session, so a leaked API key can’t create agent identities. Listing works from an API key with the api_keys.read scope. Issuing a key for a revoked agent returns agent_not_active. See Manage your agents for the full flow.
Lifecycle
A key isACTIVE until you revoke it, then REVOKED; a rotated key’s old secret stops authenticating at its expiresAt. Rotating with POST /agent-keys/{keyId}/rotate issues a replacement and keeps the old key valid for a grace period you choose, up to 24 hours, so a running agent switches over without downtime. Revoking with DELETE /agent-keys/{keyId} invalidates a key immediately, with no replacement. Either way, the secret is shown once.