Keys live under Profile → API keys. Create one key per agent or integration so usage stays attributable.
- Revoking a key takes effect immediately - the next request fails with 401.
- Keys are shown once at creation. If you lose one, revoke and re-create.
- Scopes restrict what a key may do; spending scopes can be left off entirely for read-only agents.