Kernel API Keys API
Create and manage API keys for organization and project-scoped access.
Create and manage API keys for organization and project-scoped access.
openapi: 3.1.0
info:
title: Kernel API Keys API
description: Developer tools and cloud infrastructure for AI agents to use web browsers
version: 0.1.0
servers:
- url: https://api.onkernel.com
description: API Server
security:
- bearerAuth: []
tags:
- name: API Keys
description: Create and manage API keys for organization and project-scoped access.
paths:
/org/api_keys:
get:
operationId: listApiKeys
tags:
- API Keys
summary: List API keys
description: List API keys for the authenticated organization. API keys are masked.
security:
- bearerAuth: []
parameters:
- name: limit
in: query
required: false
schema:
type: integer
default: 20
maximum: 100
description: Maximum number of results to return
- name: offset
in: query
required: false
schema:
type: integer
default: 0
description: Number of results to skip
responses:
'200':
description: List of API keys
headers:
X-Has-More:
schema:
type: boolean
description: Whether there are more results
X-Next-Offset:
schema:
type: integer
description: Offset for next page
content:
application/json:
schema:
type: array
items:
$ref: '#/components/schemas/ApiKey'
'401':
$ref: '#/components/responses/Unauthorized'
'500':
$ref: '#/components/responses/InternalError'
post:
operationId: postApiKeys
tags:
- API Keys
summary: Create an API key
description: Create a new API key within the authenticated organization.
security:
- bearerAuth: []
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CreateApiKeyRequest'
responses:
'201':
description: API key created successfully
content:
application/json:
schema:
$ref: '#/components/schemas/CreatedApiKey'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalError'
/org/api_keys/{id}:
get:
operationId: getApiKeysById
tags:
- API Keys
summary: Get an API key
description: Retrieve an API key by ID for the authenticated organization. API keys are masked.
security:
- bearerAuth: []
parameters:
- name: id
in: path
required: true
schema:
type: string
description: API key ID
responses:
'200':
description: API key details
content:
application/json:
schema:
$ref: '#/components/schemas/ApiKey'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalError'
patch:
operationId: patchApiKeysById
tags:
- API Keys
summary: Update an API key
description: Update an API key's name.
security:
- bearerAuth: []
parameters:
- name: id
in: path
required: true
schema:
type: string
description: API key ID
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/UpdateApiKeyRequest'
responses:
'200':
description: API key updated
content:
application/json:
schema:
$ref: '#/components/schemas/ApiKey'
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalError'
delete:
operationId: deleteApiKeysById
tags:
- API Keys
summary: Delete an API key
description: Delete an API key.
security:
- bearerAuth: []
parameters:
- name: id
in: path
required: true
schema:
type: string
description: API key ID
responses:
'204':
description: API key deleted.
'401':
$ref: '#/components/responses/Unauthorized'
'404':
$ref: '#/components/responses/NotFound'
'500':
$ref: '#/components/responses/InternalError'
components:
responses:
InternalError:
description: Internal Server Error
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
NotFound:
description: Resource not found
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
Unauthorized:
description: Unauthorized – missing or invalid authorization token
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
BadRequest:
description: Bad Request – invalid input
content:
application/json:
schema:
$ref: '#/components/schemas/Error'
schemas:
UpdateApiKeyRequest:
type: object
required:
- name
properties:
name:
type: string
description: New API key name
minLength: 1
maxLength: 255
example: new-api-name
ErrorDetail:
type: object
properties:
code:
type: string
description: Lower-level error code providing more specific detail
example: invalid_input
message:
type: string
description: Further detail about the error
example: Provided version string is not semver compliant
CreateApiKeyRequest:
type: object
required:
- name
properties:
name:
type: string
description: API key name (1-255 characters)
minLength: 1
maxLength: 255
example: staging
days_to_expire:
type: integer
description: Number of days until expiry, up to 3650. Use null for never.
minimum: 1
maximum: 3650
example: 30
nullable: true
project_id:
type: string
description: Unique project identifier
example: proj_abc123
nullable: true
ApiKeyCreator:
type: object
required:
- id
- email
- name
properties:
id:
type: string
description: Kernel user ID of the creator.
example: user-abc123
email:
type: string
format: email
description: Email address of the creator.
example: user@example.com
name:
type: string
nullable: true
description: Display name of the creator, if available.
example: Jane Doe
Error:
type: object
required:
- code
- message
properties:
code:
type: string
description: Application-specific error code (machine-readable)
example: bad_request
message:
type: string
description: Human-readable error description for debugging
example: 'Missing required field: app_name'
details:
type: array
description: Additional error details (for multiple errors)
items:
$ref: '#/components/schemas/ErrorDetail'
inner_error:
$ref: '#/components/schemas/ErrorDetail'
CreatedApiKey:
description: API key returned immediately after creation. Includes the plaintext key once.
allOf:
- $ref: '#/components/schemas/ApiKey'
- type: object
required:
- key
properties:
key:
type: string
description: Plaintext API key. Only returned once when the key is created.
example: sk_1234abcd
ApiKey:
type: object
required:
- id
- name
- created_at
- created_by
- expires_at
- project_id
- project_name
- masked_key
properties:
id:
type: string
description: Unique API key identifier
example: ckv9w8q2f000001l5r3j7k9m4
name:
type: string
description: API key name
example: production
created_at:
type: string
format: date-time
description: When the API key was created
created_by:
$ref: '#/components/schemas/ApiKeyCreator'
expires_at:
type: string
format: date-time
description: When the API key expires
nullable: true
project_id:
type: string
description: Project identifier for project-scoped API keys. Null means org-wide.
example: proj_abc123
nullable: true
project_name:
type: string
description: Project name for project-scoped API keys. Null means the key is org-wide or the project name is unavailable.
example: Production
nullable: true
masked_key:
type: string
description: Masked version of the API key
example: sk_1234...abcd
securitySchemes:
bearerAuth:
type: http
scheme: bearer