> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pioneer.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Pioneer API key management: create, list, and revoke

> Create, list, and revoke Pioneer API keys programmatically. The full key value is returned only at creation — store it immediately in a secrets manager.

Every request to the Pioneer API requires an API key passed in the `X-API-Key` header. You can manage your keys programmatically using these endpoints — useful for rotating keys in CI/CD pipelines, issuing scoped keys for different services, or automating key lifecycle management.

<Tip>
  Store API keys in environment variables rather than hardcoding them in source code. For example, set `PIONEER_API_KEY` in your environment and read it at runtime. Never commit API keys to version control.
</Tip>

***

## Create an API key

`POST /create-api-key`

Generates a new API key associated with your account. The full key value is returned only once at creation time — store it securely immediately.

**Request body**

<ParamField body="name" type="string" required>
  A descriptive name to identify this key. Use names that reflect the key's purpose or the service it belongs to, for example `"ci-pipeline"` or `"production-inference"`.
</ParamField>

```bash theme={null}
curl -X POST https://api.pioneer.ai/create-api-key \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "my-integration-key"}'
```

**Response**

<ResponseField name="key" type="string">
  The full API key value. This is the only time it is returned in plaintext — copy it immediately and store it somewhere secure such as a secrets manager or environment variable.
</ResponseField>

<ResponseField name="name" type="string">
  The name you assigned to the key.
</ResponseField>

<ResponseField name="created_at" type="string">
  ISO 8601 timestamp of when the key was created.
</ResponseField>

<Warning>
  The full key value is only returned at creation time. If you lose it, you must revoke the key and create a new one.
</Warning>

***

## List API keys

`GET /list-api-keys`

Returns all API keys associated with your account. Key values are masked in the response — only metadata such as name and creation date are returned.

```bash theme={null}
curl https://api.pioneer.ai/list-api-keys \
  -H "X-API-Key: YOUR_API_KEY"
```

**Response**

<ResponseField name="keys" type="object[]">
  Array of API key metadata objects.

  <Expandable title="key properties">
    <ResponseField name="id" type="string">
      Unique identifier for the key. Use this ID when revoking the key.
    </ResponseField>

    <ResponseField name="name" type="string">
      The name assigned to this key.
    </ResponseField>

    <ResponseField name="created_at" type="string">
      ISO 8601 creation timestamp.
    </ResponseField>

    <ResponseField name="last_used_at" type="string">
      ISO 8601 timestamp of the most recent request made with this key, if available.
    </ResponseField>
  </Expandable>
</ResponseField>

***

## Revoke an API key

`DELETE /delete-api-key`

Permanently revokes an API key. Any requests using the revoked key will immediately receive `401 Unauthorized` responses.

**Request body**

<ParamField body="key_id" type="string" required>
  The unique ID of the key to revoke, as returned by `GET /list-api-keys`.
</ParamField>

```bash theme={null}
curl -X DELETE https://api.pioneer.ai/delete-api-key \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"key_id": "YOUR_KEY_ID"}'
```

<Warning>
  Revoking a key is immediate and irreversible. Ensure any services using the key are updated to use a replacement key before revoking the old one to avoid service interruptions.
</Warning>

Returns `204 No Content` on success.
