Account → Account Security → My API key
Generate a personal API key for programmatic access to MisterShell. Every user can have at most one API key at a time. Scripts, CI pipelines, and custom integrations authenticate by passing the key as a bearer token.
What you can do
- Generate a new API key.
- Replace your existing key (invalidates the old one).
- Revoke your key.
- See when the key was last used.
Generate your first key
- Click Generate New Key.
- Choose an Expiration date. If your administrator sets a maximum lifetime, the latest permitted date is prefilled and expiration is required. Otherwise you may leave it empty for no expiration. Dates expire at 00:00 UTC.
- Click Generate.
- A dialog shows the new key value, masked by default — use the eye icon to reveal it and the copy icon to copy it to your clipboard. This is the only time the full key is available — store it in a password manager or secrets store before closing the dialog.
- Click I’ve Saved It to close.
After generation, only the key prefix is displayed on this page (the last characters are never stored in plaintext).
Replace your key
Replace your key when you think it may have been exposed, or on a rotation schedule.
- Click Generate New Key (shown as a rotate-style button when a key already exists).
- In Generate API Key, choose a valid expiration date and click Generate. Your existing key remains in place while you fill the form.
- In Replace API Key, click Replace to confirm. The lifetime policy is checked again before deleting the existing key and requesting its replacement. Replacement uses separate delete and create requests: if creation fails after deletion, generate a new key before applications can resume.
- Save the new key value as described above.
Revoke your key
- Click Revoke Key.
- Click Revoke in the confirmation dialog. The key is deleted permanently; there is no undo.
After revocation, you have no key until you generate a new one. Applications that depended on the key will fail to authenticate.
Lifetime policy
Administrators configure max_api_key_lifetime under Advanced Settings. It is a whole number of days from creation (0–3650); 0 means unlimited and is the default. Positive limits require an expiration no later than the configured lifetime. Existing keys keep their saved expiration when the setting changes.
The form loads the policy when opened and checks it again before submission. If settings cannot be loaded, use Retry; key creation stays disabled. If a limit changes, your entered date is preserved so you can correct it. The API enforces the policy independently of the browser.
Key metadata
| Field | Notes |
|---|---|
| Key Prefix | The first characters of your key, echoed on the page so you can identify which key is in use. |
| Created | When the key was generated. |
| Expires | Date the key will stop working, or Never. |
| Last Used | Timestamp of the most recent request authenticated with this key, or Never. |
Using the key
Pass it as a bearer token in the Authorization header:
Authorization: Bearer <your-api-key>
For the complete list of available endpoints, see the API reference (separate document).
Permissions
None — every user can manage their own API key.