Reference

API keys

Updated 1 Oct 2026

On this page

For agents

Load this page when: you need to create or revoke an API key, or decide how a client should authenticate

  • Create a key in Settings or with trove auth login. The full key is shown once.
  • Store a key like a password. The CLI keeps it in plain text in ~/.trove/config.toml.
  • Revoke a leaked key in Settings. A revoked key fails with Invalid or revoked API key.

An API key is a long-lived secret that signs in a script, a server or the CLI as you. Trove stores only a hash of it, so it cannot show you a key again.

Create a key

Pick one of three ways.

  1. Open https://heytrove.ai/settings?tab=developers, choose to create a key, and name it with 1 to 50 characters. Copy the key from the dialog. It is shown once.
  2. Run trove auth login. The browser flow creates a key and stores it for the CLI.
  3. Run trove auth login --with-token to sign in with a key you already have. The CLI reads it from stdin or a hidden prompt.

Creating keys is limited to 5 per minute. The limit covers both the web page and trove auth login.

Prefixes

New keys start with trove_. Older keys start with ck_ and keep working. In examples, a key is written trove_your_key.

Scopes

Every key you create has the cli scope. It gives access to your own library over REST and MCP.

ScopeWho has itWhat it allows
cliEvery key you createYour library, shelves, manuscripts, teams, settings and agents
admin:deployTrove staff onlyInternal deployment. You cannot create it

Two route groups need a cli key and refuse OAuth connector tokens: PATCH /user/config/agents and /user/agents. See Account API.

Store a key

The CLI saves its key in plain text in ~/.trove/config.toml. Treat that file like a password. Do not commit a key, paste it into a chat, or print it in logs. Put keys for CI in your CI secret store.

Revoke a key

Open https://heytrove.ai/settings?tab=developers and revoke the key. It stops working at once. Any call that uses it fails with Invalid or revoked API key. Revoking one key does not touch your others.

Keys and OAuth connector tokens

API keyOAuth connector token
Prefixtrove_ or ck_ck_oauth_
Made byYou, in Settings or with trove auth loginA client you sign in with, such as Claude or ChatGPT
Works on RESTYesNo. It fails with Token resource binding does not match request
Works on MCPYes, with all four scopesYes, with the scopes you granted
Best forScripts, servers, CI and the CLIClaude, Cowork and ChatGPT

See REST API and MCP server.

    API keys | Trove