API keys
Give scripts scoped collection access. Create a key, set its expiry, store its secret safely, and revoke or replace it.
Use an API key when a script or your own backend needs access to EximAgent collections without an interactive assistant sign-in. For assistant tools, prefer the MCP server's OAuth flow.
Create a key
Open Settings → API keys in the product app and sign in to the account that owns the collections.
- Choose a name that identifies the script or integration.
- Choose which collections it may access and the access level for each.
- Set a finite expiry.
- Create the key and save the secret immediately in a secret manager or a server-side environment variable.
| Access level | Intended use |
|---|---|
| None | Exclude a collection from this key |
| Read | Read data from the selected collection |
| Write | Allow supported mutations on the selected collection |
Grant the least access your integration needs. Collection access does not make the key an unrestricted account, administrator, or all-tools credential.
Send a request
Send the key in the Authorization header. For example, with the key already
stored in the EXIMAGENT_API_KEY environment variable:
curl --fail-with-body \
-H "Authorization: Bearer ${EXIMAGENT_API_KEY}" \
https://cli.eximagent.ai/api/collections
The service applies the credential's permissions and expiry to each request. An API key is not a separate usage allowance: applicable work is charged to its account. Read the response's credit usage and error details before retrying.
For CLI sign-in and named profiles, see authentication. Do not assume a collection key can replace every CLI or MCP credential.
Check creation before retrying
If the app loses contact during creation, use its Check creation recovery action before trying again. An interrupted response does not prove the key was never created.
If creation completed but the secret was not received, create a replacement and revoke the unusable credential. The app cannot recover a secret that is no longer available.
Revoke or replace a key
Use the API key inventory in Settings to review and revoke credentials you no longer need. Keys stop working after expiry or revocation.
To replace a key in an integration:
- Create a replacement with only the required collection access.
- Update the integration's secret and verify a permitted read request.
- Revoke the old key.
If a key was exposed, revoke it immediately rather than waiting for expiry. Revoking a key does not delete the collections it could access.