API keys
Authenticating to opsen, and what to do when one leaks.
Creating one
On the keys page. Shown once — opsen stores a hash, so a key that is lost is replaced rather than recovered.
export OPSEN_API_KEY=osk_...Using one
Authorization: Bearer osk_...
x-api-key: osk_...Revoking
Immediate. In-flight requests using it fail. Revoke first and re-issue after — a key you suspect is a key you have lost.
These are not provider keys
| kind | what it is |
|---|---|
| opsen API key | authenticates you to opsen |
| provider key | your Anthropic or OpenAI key, held by opsen, never in the sandbox |
| session token | minted per session, injected into the sandbox, dies with it |
| credential | your GitHub or Slack, lent to a run and attached at egress |