openapi: 3.1.0 info: title: Kernel API Keys API description: Developer tools and cloud infrastructure for AI agents to use web browsers version: 0.1.0 servers: - url: https://api.onkernel.com description: API Server security: - bearerAuth: [] tags: - name: API Keys description: Create and manage API keys for organization and project-scoped access. paths: /org/api_keys: get: operationId: listApiKeys tags: - API Keys summary: List API keys description: List API keys for the authenticated organization. API keys are masked. security: - bearerAuth: [] parameters: - name: limit in: query required: false schema: type: integer default: 20 maximum: 100 description: Maximum number of results to return - name: offset in: query required: false schema: type: integer default: 0 description: Number of results to skip responses: '200': description: List of API keys headers: X-Has-More: schema: type: boolean description: Whether there are more results X-Next-Offset: schema: type: integer description: Offset for next page content: application/json: schema: type: array items: $ref: '#/components/schemas/ApiKey' '401': $ref: '#/components/responses/Unauthorized' '500': $ref: '#/components/responses/InternalError' post: operationId: postApiKeys tags: - API Keys summary: Create an API key description: Create a new API key within the authenticated organization. security: - bearerAuth: [] requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/CreateApiKeyRequest' responses: '201': description: API key created successfully content: application/json: schema: $ref: '#/components/schemas/CreatedApiKey' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' /org/api_keys/{id}: get: operationId: getApiKeysById tags: - API Keys summary: Get an API key description: Retrieve an API key by ID for the authenticated organization. API keys are masked. security: - bearerAuth: [] parameters: - name: id in: path required: true schema: type: string description: API key ID responses: '200': description: API key details content: application/json: schema: $ref: '#/components/schemas/ApiKey' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' patch: operationId: patchApiKeysById tags: - API Keys summary: Update an API key description: Update an API key's name. security: - bearerAuth: [] parameters: - name: id in: path required: true schema: type: string description: API key ID requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/UpdateApiKeyRequest' responses: '200': description: API key updated content: application/json: schema: $ref: '#/components/schemas/ApiKey' '400': $ref: '#/components/responses/BadRequest' '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' delete: operationId: deleteApiKeysById tags: - API Keys summary: Delete an API key description: Delete an API key. security: - bearerAuth: [] parameters: - name: id in: path required: true schema: type: string description: API key ID responses: '204': description: API key deleted. '401': $ref: '#/components/responses/Unauthorized' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalError' components: responses: InternalError: description: Internal Server Error content: application/json: schema: $ref: '#/components/schemas/Error' NotFound: description: Resource not found content: application/json: schema: $ref: '#/components/schemas/Error' Unauthorized: description: Unauthorized – missing or invalid authorization token content: application/json: schema: $ref: '#/components/schemas/Error' BadRequest: description: Bad Request – invalid input content: application/json: schema: $ref: '#/components/schemas/Error' schemas: UpdateApiKeyRequest: type: object required: - name properties: name: type: string description: New API key name minLength: 1 maxLength: 255 example: new-api-name ErrorDetail: type: object properties: code: type: string description: Lower-level error code providing more specific detail example: invalid_input message: type: string description: Further detail about the error example: Provided version string is not semver compliant CreateApiKeyRequest: type: object required: - name properties: name: type: string description: API key name (1-255 characters) minLength: 1 maxLength: 255 example: staging days_to_expire: type: integer description: Number of days until expiry, up to 3650. Use null for never. minimum: 1 maximum: 3650 example: 30 nullable: true project_id: type: string description: Unique project identifier example: proj_abc123 nullable: true ApiKeyCreator: type: object required: - id - email - name properties: id: type: string description: Kernel user ID of the creator. example: user-abc123 email: type: string format: email description: Email address of the creator. example: user@example.com name: type: string nullable: true description: Display name of the creator, if available. example: Jane Doe Error: type: object required: - code - message properties: code: type: string description: Application-specific error code (machine-readable) example: bad_request message: type: string description: Human-readable error description for debugging example: 'Missing required field: app_name' details: type: array description: Additional error details (for multiple errors) items: $ref: '#/components/schemas/ErrorDetail' inner_error: $ref: '#/components/schemas/ErrorDetail' CreatedApiKey: description: API key returned immediately after creation. Includes the plaintext key once. allOf: - $ref: '#/components/schemas/ApiKey' - type: object required: - key properties: key: type: string description: Plaintext API key. Only returned once when the key is created. example: sk_1234abcd ApiKey: type: object required: - id - name - created_at - created_by - expires_at - project_id - project_name - masked_key properties: id: type: string description: Unique API key identifier example: ckv9w8q2f000001l5r3j7k9m4 name: type: string description: API key name example: production created_at: type: string format: date-time description: When the API key was created created_by: $ref: '#/components/schemas/ApiKeyCreator' expires_at: type: string format: date-time description: When the API key expires nullable: true project_id: type: string description: Project identifier for project-scoped API keys. Null means org-wide. example: proj_abc123 nullable: true project_name: type: string description: Project name for project-scoped API keys. Null means the key is org-wide or the project name is unavailable. example: Production nullable: true masked_key: type: string description: Masked version of the API key example: sk_1234...abcd securitySchemes: bearerAuth: type: http scheme: bearer