opsen
opsen

API keys

Authenticating to opsen, and what to do when one leaks.

Creating one

On the keys page. Shown once — opsen stores a hash, so a key that is lost is replaced rather than recovered.

export OPSEN_API_KEY=osk_...

Using one

Authorization: Bearer osk_...
x-api-key: osk_...

Revoking

Immediate. In-flight requests using it fail. Revoke first and re-issue after — a key you suspect is a key you have lost.

These are not provider keys

kindwhat it is
opsen API keyauthenticates you to opsen
provider keyyour Anthropic or OpenAI key, held by opsen, never in the sandbox
session tokenminted per session, injected into the sandbox, dies with it
credentialyour GitHub or Slack, lent to a run and attached at egress