# Keys and scopes

Create, scope, inspect, and revoke API keys.

Keys belong to a workspace. Workspace owners and admins create and revoke them in the console. Members can see the prefix, name, and usage of each key.

## Scopes [#scopes]

Each key carries one or both scopes:

| scope    | grants                                    |
| -------- | ----------------------------------------- |
| `papers` | `/v1/search` and `/v1/resolve`            |
| `pdf`    | No public endpoint uses this scope today. |

Calling an endpoint outside the key's scopes answers `403 InsufficientScope`. Pick the smallest set the integration needs.

## Inspect the current key [#inspect-the-current-key]

<CodeGroup>
  ```bash title="cURL"
  curl https://api.anara.com/v1/keys/current \
    -H "Authorization: Bearer $ANARA_API_KEY"
  ```

  ```python title="Python"
  import os
  import requests

  response = requests.get(
      "https://api.anara.com/v1/keys/current",
      headers={"Authorization": f"Bearer {os.environ['ANARA_API_KEY']}"},
  )
  print(response.json())
  ```

  ```ts title="TypeScript"
  const response = await fetch("https://api.anara.com/v1/keys/current", {
    method: "GET",
    headers: {
      Authorization: `Bearer ${process.env.ANARA_API_KEY}`,
    },
  });
  console.log(await response.json());
  ```
</CodeGroup>

```json title="Response"
{ "id": "k_…", "name": "prod", "keyPrefix": "ana_live_Ab12", "scopes": ["papers"], "workspaceId": "…", "createdAt": "…", "revokedAt": null }
```

## Revoke [#revoke]

Revoke in the console, or let the key revoke itself, for example from an incident runbook:

<CodeGroup>
  ```bash title="cURL"
  curl -X POST https://api.anara.com/v1/keys/current/revoke \
    -H "Authorization: Bearer $ANARA_API_KEY"
  ```

  ```python title="Python"
  import os
  import requests

  response = requests.post(
      "https://api.anara.com/v1/keys/current/revoke",
      headers={"Authorization": f"Bearer {os.environ['ANARA_API_KEY']}"},
  )
  print(response.json())
  ```

  ```ts title="TypeScript"
  const response = await fetch("https://api.anara.com/v1/keys/current/revoke", {
    method: "POST",
    headers: {
      Authorization: `Bearer ${process.env.ANARA_API_KEY}`,
    },
  });
  console.log(await response.json());
  ```
</CodeGroup>

Revocation takes effect at once. Every later request with that key answers `401` with the message `API key revoked`.
