Reference
API keys
Updated 1 Oct 2026
For agents
Load this page when: you need to create or revoke an API key, or decide how a client should authenticate
- Create a key in Settings or with trove auth login. The full key is shown once.
- Store a key like a password. The CLI keeps it in plain text in ~/.trove/config.toml.
- Revoke a leaked key in Settings. A revoked key fails with Invalid or revoked API key.
An API key is a long-lived secret that signs in a script, a server or the CLI as you. Trove stores only a hash of it, so it cannot show you a key again.
Create a key
Pick one of three ways.
- Open
https://heytrove.ai/settings?tab=developers, choose to create a key, and name it with 1 to 50 characters. Copy the key from the dialog. It is shown once. - Run
trove auth login. The browser flow creates a key and stores it for the CLI. - Run
trove auth login --with-tokento sign in with a key you already have. The CLI reads it from stdin or a hidden prompt.
Creating keys is limited to 5 per minute. The limit covers both the web page and trove auth login.
Prefixes
New keys start with trove_. Older keys start with ck_ and keep working. In examples, a key is written trove_your_key.
Scopes
Every key you create has the cli scope. It gives access to your own library over REST and MCP.
| Scope | Who has it | What it allows |
|---|---|---|
cli | Every key you create | Your library, shelves, manuscripts, teams, settings and agents |
admin:deploy | Trove staff only | Internal deployment. You cannot create it |
Two route groups need a cli key and refuse OAuth connector tokens: PATCH /user/config/agents and /user/agents. See Account API.
Store a key
The CLI saves its key in plain text in ~/.trove/config.toml. Treat that file like a password. Do not commit a key, paste it into a chat, or print it in logs. Put keys for CI in your CI secret store.
Revoke a key
Open https://heytrove.ai/settings?tab=developers and revoke the key. It stops working at once. Any call that uses it fails with Invalid or revoked API key. Revoking one key does not touch your others.
Keys and OAuth connector tokens
| API key | OAuth connector token | |
|---|---|---|
| Prefix | trove_ or ck_ | ck_oauth_ |
| Made by | You, in Settings or with trove auth login | A client you sign in with, such as Claude or ChatGPT |
| Works on REST | Yes | No. It fails with Token resource binding does not match request |
| Works on MCP | Yes, with all four scopes | Yes, with the scopes you granted |
| Best for | Scripts, servers, CI and the CLI | Claude, Cowork and ChatGPT |
See REST API and MCP server.