---
title: "API Keys"
description: "List, create, and revoke TurboPentest API keys through the API. Key values are masked after creation, leaving only the tp_ prefix for identification."
canonical: https://turbopentest.com/docs/api/keys
source: "TurboPentest Docs"
---

# API Keys

## List API keys

```
GET /api/keys
```

Returns all active (non-revoked) API keys for your account. Key values are masked after creation - only the `tp_` prefix plus the first 8 characters is stored for identification.

**Response** `200 OK`

```json
[
  {
    "id": "3f8b2c1d-9e0a-4b5c-8d7e-6f5a4b3c2d10",
    "name": "CI/CD Pipeline",
    "prefix": "tp_a1b2c3d4",
    "createdAt": "2025-01-05T09:00:00Z",
    "lastUsedAt": "2025-02-14T15:30:00Z"
  }
]
```

## Create API key

```
POST /api/keys
```

Creates a new API key. The full key value is only returned once at creation time.

**Request body**

| Field | Type | Required | Description |
|-------|------|----------|-------------|
| `name` | string | Yes | A descriptive name for the key |

**Response** `201 Created`

```json
{
  "id": "5a7c9e1b-3d2f-4a6b-8c0d-1e2f3a4b5c60",
  "name": "GitHub Actions",
  "prefix": "tp_a1b2c3d4",
  "key": "tp_a1b2c3d4e5f60718293a4b5c6d7e8f90"
}
```

Save the `key` value immediately - it cannot be retrieved again.

## Revoke API key

```
DELETE /api/keys/:id
```

Permanently revokes an API key. Any integrations using this key will stop working.

**Response** `200 OK`

```json
{ "success": true }
```
