---
title: "API keys"
description: "Use when you create, store or revoke a Trove API key, need to know what a key can do, or want to choose between an API key and an OAuth connector token."
url: https://docs.heytrove.ai/reference/api-keys
updated: 2026-10-01
---

# API keys

> Load this page when: you need to create or revoke an API key, or decide how a client should authenticate

## For agents

- Create a key in Settings or with trove auth login. The full key is shown once.
- Store a key like a password. The CLI keeps it in plain text in ~/.trove/config.toml.
- Revoke a leaked key in Settings. A revoked key fails with Invalid or revoked API key.

An API key is a long-lived secret that signs in a script, a server or the CLI as you. Trove stores only a hash of it, so it cannot show you a key again.

## Create a key

Pick one of three ways.

1. Open `https://heytrove.ai/settings?tab=developers`, choose to create a key, and name it with 1 to 50 characters. Copy the key from the dialog. It is shown once.
2. Run `trove auth login`. The browser flow creates a key and stores it for the CLI.
3. Run `trove auth login --with-token` to sign in with a key you already have. The CLI reads it from stdin or a hidden prompt.

Creating keys is limited to 5 per minute. The limit covers both the web page and `trove auth login`.

## Prefixes

New keys start with `trove_`. Older keys start with `ck_` and keep working. In examples, a key is written `trove_your_key`.

## Scopes

Every key you create has the `cli` scope. It gives access to your own library over REST and MCP.

| Scope | Who has it | What it allows |
| --- | --- | --- |
| `cli` | Every key you create | Your library, shelves, manuscripts, teams, settings and agents |
| `admin:deploy` | Trove staff only | Internal deployment. You cannot create it |

Two route groups need a `cli` key and refuse OAuth connector tokens: `PATCH /user/config/agents` and `/user/agents`. See [Account API](https://docs.heytrove.ai/reference/api/account.md).

## Store a key

The CLI saves its key in plain text in `~/.trove/config.toml`. Treat that file like a password. Do not commit a key, paste it into a chat, or print it in logs. Put keys for CI in your CI secret store.

## Revoke a key

Open `https://heytrove.ai/settings?tab=developers` and revoke the key. It stops working at once. Any call that uses it fails with `Invalid or revoked API key`. Revoking one key does not touch your others.

## Keys and OAuth connector tokens

| | API key | OAuth connector token |
| --- | --- | --- |
| Prefix | `trove_` or `ck_` | `ck_oauth_` |
| Made by | You, in Settings or with `trove auth login` | A client you sign in with, such as Claude or ChatGPT |
| Works on REST | Yes | No. It fails with `Token resource binding does not match request` |
| Works on MCP | Yes, with all four scopes | Yes, with the scopes you granted |
| Best for | Scripts, servers, CI and the CLI | Claude, Cowork and ChatGPT |

See [REST API](https://docs.heytrove.ai/reference/api.md) and [MCP server](https://docs.heytrove.ai/reference/mcp.md).
