> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.lakera.ai/docs/red/management-api-keys/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.lakera.ai/_mcp/server. # Management API — Red Team API Keys Manage the folder-scoped **Red Team API Keys** used with the [SDK](/docs/red/sdk-quickstart). All endpoints require a Management API Key and are scoped to its organization — see the [Overview](/docs/red/management-api-overview) for authentication and error conventions. Keys created here are folder-scoped: a key can only access the targets, scans, and evaluations in its folder. The Management API cannot create another Management API Key — that lifecycle is dashboard-only. The secret is returned only once, when the key is created or rotated. It is never stored in plaintext and cannot be retrieved afterward, so record it at creation time. ## List keys `GET /management/folders/{folderId}/keys` Returns metadata for each key in the folder. The secret is never included in a listing. ```bash curl -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \ https://$LAKERA_RED_HOST/management/folders/{folderId}/keys ``` ```json { "keys": [ { "id": "...", "folderId": "...", "name": "CI key", "prefix": "sk_lr_...", "createdAt": 1786546819835, "revokedAt": 1786550000000, "lastUsedAt": 1786549000000 } ] } ``` `revokedAt` and `lastUsedAt` are present only when applicable. ## Create a key `POST /management/folders/{folderId}/keys` | Field | Type | Required | Notes | | ------ | ------ | -------- | -------------------------------- | | `name` | string | yes | 1–200 characters after trimming. | ```bash curl -X POST -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \ -H "Content-Type: application/json" \ -d '{"name": "CI key"}' \ https://$LAKERA_RED_HOST/management/folders/{folderId}/keys ``` Responds `201` with the key id and the secret: ```json { "keyId": "...", "key": "sk_lr_..." } ``` ## Rotate a key `POST /management/folders/{folderId}/keys/{keyId}/rotate` Issues a replacement key with the same name and immediately revokes the old one, so the two are never valid at the same time. ```bash curl -X POST -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \ https://$LAKERA_RED_HOST/management/folders/{folderId}/keys/{keyId}/rotate ``` Responds with the new key id and secret: ```json { "keyId": "...", "key": "sk_lr_..." } ``` ## Revoke a key `DELETE /management/folders/{folderId}/keys/{keyId}` ```bash curl -X DELETE -H "Authorization: Bearer $LAKERA_MANAGEMENT_KEY" \ https://$LAKERA_RED_HOST/management/folders/{folderId}/keys/{keyId} ``` Responds `204`. Revoking an already-revoked key is a no-op.