Authentication
How API keys work: creating them, sending them, expiry, rotation and what a key can never do.
Every request is authenticated with a developer API key. Keys start with aw_ak_ and are created by a workspace admin in Workspace → API keys.
Send the key
curl https://api.agent-works.ai/tasks \
-H "Authorization: Bearer aw_ak_…"
The /v1 endpoints also accept X-API-Key: aw_ak_….
Keys are for server-to-server use. The /v1 endpoints refuse requests that come from a browser. Never ship a key in front-end code.
What a key is
- A key belongs to one workspace and acts as the person who created it. Role limits apply: a key cannot do what that person cannot do.
- A key carries scopes. An endpoint outside those scopes answers
403. See Scopes. - The key itself is shown once, at creation. AgentWorks stores only a hash.
- When the person who created the key is deactivated, the key stops working.
- A workspace can have up to 10 active keys.
Expiry
Choose how long a key is valid when you create it: 30, 90, 180, 365 or 730 days, or no expiry. The default is 90 days and the maximum is two years. An expired key answers 401.
Workspace admins get a notification 7 days and 1 day before a key expires. The key list also flags keys that are expired, about to expire, or unused for 90 days.
Rotate a key
Rotating gives you a new secret with the same name, scopes and expiry, and switches the old one off. To rotate without downtime, create a second key, deploy it to your integration, then revoke the old one.
Change scopes later
Use Edit scopes on a key to add or remove permissions. The change applies to the key's next request; the secret stays the same.
Revoke a key
Revoke switches a key off immediately. Do this as soon as a key may have been exposed — for example pasted into a chat, a ticket or a log.
What a key can never do
- Approve or reject a request that is waiting for a person.
- Change approval settings, per-action confirmations or the personal-data policy.
- Act in another workspace. A key from an agency workspace works in the agency workspace only; see Agencies.