> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.lakera.ai/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.lakera.ai/_mcp/server.

# Management API — Red Team API Keys

Manage the folder-scoped **Red Team API Keys** used with the
[SDK](/docs/red/sdk-quickstart). All endpoints require a Management API Key and are
scoped to its organization — see the [Overview](/docs/red/management-api-overview) for
authentication and error conventions.

Keys created here are folder-scoped: a key can only access the targets, scans, and
evaluations in its folder. The Management API cannot create another Management API Key —
that lifecycle is dashboard-only.

The secret is returned only once, when the key is created or rotated. It is never stored
in plaintext and cannot be retrieved afterward, so record it at creation time.

## List keys

`GET /management/folders/{folderId}/keys`

Returns metadata for each key in the folder. The secret is never included in a listing.

```bash
curl -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  https://$LAKERA_RED_HOST/management/folders/{folderId}/keys
```

```json
{
  "keys": [
    {
      "id": "...",
      "folderId": "...",
      "name": "CI key",
      "prefix": "sk_lr_...",
      "createdAt": 1786546819835,
      "revokedAt": 1786550000000,
      "lastUsedAt": 1786549000000
    }
  ]
}
```

`revokedAt` and `lastUsedAt` are present only when applicable.

## Create a key

`POST /management/folders/{folderId}/keys`

| Field  | Type   | Required | Notes                            |
| ------ | ------ | -------- | -------------------------------- |
| `name` | string | yes      | 1–200 characters after trimming. |

```bash
curl -X POST -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "CI key"}' \
  https://$LAKERA_RED_HOST/management/folders/{folderId}/keys
```

Responds `201` with the key id and the secret:

```json
{ "keyId": "...", "key": "sk_lr_..." }
```

## Rotate a key

`POST /management/folders/{folderId}/keys/{keyId}/rotate`

Issues a replacement key with the same name and immediately revokes the old one, so the
two are never valid at the same time.

```bash
curl -X POST -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  https://$LAKERA_RED_HOST/management/folders/{folderId}/keys/{keyId}/rotate
```

Responds with the new key id and secret:

```json
{ "keyId": "...", "key": "sk_lr_..." }
```

## Revoke a key

`DELETE /management/folders/{folderId}/keys/{keyId}`

```bash
curl -X DELETE -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \
  https://$LAKERA_RED_HOST/management/folders/{folderId}/keys/{keyId}
```

Responds `204`. Revoking an already-revoked key is a no-op.