Skip to content
ajar.Book a demo

Management API

Automate API key provisioning and revocation for your workspace.

Create a management key

Workspace owners can create management keys under Settings → API keys. Choose keys:read, keys:create and/or keys:revoke, plus the maximum connector permission and connector scope your automation can mint. The secret is shown once, belongs to one workspace, and must expire within 90 days. Store it on your server. Connector keys cannot call the Management API, and management keys cannot call connectors or mint other management keys.

List, create and revoke connector keys

Use the account API base https://ajar-auth.fly.dev, separate from the connector API. Authenticate with Authorization: Bearer YOUR_MANAGEMENT_SECRET. GET /v1/management/api-keys?page=1 returns 25 keys per page with a total count and masked prefixes. POST /v1/management/api-keys accepts name, permission (read or read-write), scope (all or a connector slug), expiresAt (RFC 3339) and optional requestLimit with period (minute, day, month or total) and requests. Include a unique x-idempotency-key header for each creation. The minted key cannot exceed the management key's permission, connector scope or expiry. Creation requires active workspace entitlement. DELETE /v1/management/api-keys/{id} revokes a connector key immediately; repeating it succeeds. List and revoke remain available when billing access ends.

Safe retries and rotation

Creation returns HTTP 201 with the new id and secret. Retrying the same idempotency key with the identical request body returns HTTP 200 with the existing id, secret: null and replayed: true; no extra key is minted. Different request bytes with the same idempotency key return HTTP 409. If the first response was lost, revoke that returned id and create a replacement using a new idempotency key. Secrets cannot be recovered. Rotate a management key by creating a replacement, updating your automation and revoking the old key. Revoking a management key does not revoke connector keys it already minted.

Access and activity

Every call checks that the key is active and its issuer remains an unsuspended workspace owner. Removal or demotion permanently revokes that owner's management keys. Parsed authenticated requests are limited to 60 per key per UTC minute, including permission and validation failures; HTTP 429 includes Retry-After. Management requests do not consume connector quota. Owners can inspect the last 50 management activity records under API keys, including the action, key and target IDs, status and time. Secrets and request payloads are excluded. This first version manages connector keys; invitations, membership, organization creation/deletion and billing automation are not exposed.