Skip to Content
REST APIAuthentication

Authentication

Every Skyelight API request carries a token as a bearer token in the Authorization header:

curl https://app.skyelight.ai/api/v1/workspaces \
  -H "Authorization: Bearer sky_..."

A request with no token, a malformed header, or an invalid, expired or revoked token gets a 401. See Errors and limits.

The API accepts two kinds of token. Each one stands for a person and reaches what that person can reach.


Personal tokens

A personal token starts with sky_. Use it for scripts, CI jobs and the local MCP server.

Create one

  1. In the Skyelight web app, go to Account Settings API Keys and click Create.
  2. Enter a name and choose how long the token lasts.
  3. Copy the token. Skyelight shows it once. It stores only a hash of the token and its first 12 characters, so it can’t show the full token again.

To create a token, you need an owner, admin or collaborator role in the organization, on a plan that includes agent tools. See Plans and billing.

What a token can reach

  • One organization. A token belongs to the organization you created it in and only reaches workspaces in that organization. If you work in two organizations, create a token in each.
  • Your own access. In that organization, a token reaches the workspaces you are a member of, with the role you hold in each.

Lifetimes and limits

  • A token lasts 1, 7, 30, 60, 90, 180 or 365 days, or never expires.
  • You can have up to 10 active tokens per organization.
  • The API Keys page lists each token’s name, its first characters and its expiry date.

Revoking

To revoke a token, open its menu on the API Keys page and click Revoke. The token stops working immediately.

Skyelight also revokes your tokens for an organization when you no longer hold a paid seat there: when you become a reviewer in every workspace, are removed, or leave. Getting a seat back doesn’t restore revoked tokens. Create new ones.

OAuth access tokens

When you connect a coding agent over MCP, the agent signs you in with OAuth in the browser and receives an access token. The API also accepts these tokens. An OAuth access token has your account’s access in every organization you belong to.

The agent manages this token. For anything you configure yourself, use a personal token.

Retired workspace keys

Workspace API keys, which start with sk_live_, no longer work. Every request made with one gets a 401. Replace them with personal tokens.

Keeping tokens safe

A token acts as you. Anyone who has it can read your workspaces and reply as you until the token expires or you revoke it.

  • Keep tokens out of source control. Load them from the environment or from your CI’s secret store.
  • Use short lifetimes. Use a token with no expiry only where rotating it is impractical.
  • Use one token per machine or job, and name it after where it is used, so you can revoke one without breaking the others.
  • Revoke a token as soon as you suspect it has leaked.
Last updated on