API keys
A key is what lets a machine, script or CI job use your library. You can have several, and revoke any of them at any time.
What a key is
A key looks like svk_live_ followed by a long random string. It identifies your account and library: anyone who has it can read your skills, so treat it like a password. SkilVault stores only a one-way fingerprint of each key, never the key itself.
Create a key
- Open Install in the sidebar, choose the API keys tab, and press Create key.
- Give it a name that says where it will be used (up to 64 characters), for example
work laptoporci. - Press Generate key, then Copy. This is the only time the full key is shown.
The table lists each key's name, its first characters (so you can recognise it), when it was last used and when it was created. Most people should use Connect this machine on the Install page instead, which creates a key and gives you the command to install it — see Connecting a machine.
Revoke a key
Press Revoke next to a key, then Confirm? within a few seconds (a second click prevents accidents). The key stops working immediately; any machine still using it will get an unknown or revoked API key error. Revoking frees a key slot.
Rotate a key
To replace a key without downtime:
- Create a new key.
- Put it in the machine's
~/.config/skilvault/config(or run a fresh Connect command). - Check it works with
skilvault list. - Revoke the old key.
On the free plan (1 key) there is no spare slot, so revoke the old key first and accept a short gap.
How many keys you can have
The number of active keys depends on your plan — see Plans & billing for the current limits. At the limit, Create key is disabled with a note. If you move to a plan that allows fewer keys, the oldest keys beyond the new limit are revoked automatically.
Keeping keys safe
- Use a separate key per machine or job, so one leak does not force you to reconnect everything.
- Never commit a key to a repository or paste it into a shared chat. In CI, keep it in the platform's secret store.
- The connect command contains your key. Treat terminal history and shared screens with care.
- Send a key in an
Authorization: Bearerheader, as the client does — see API reference. A?k=query parameter still works for older clients, but URLs tend to end up in logs.
If a key leaks or is lost
A lost key cannot be recovered — it is not stored. Revoke it and create a new one. Also note that completing a password reset revokes all of your keys (see Your account).