Groundeddocs
For team owners

API keys

Personal and team service keys, their scopes and restrictions, and how to keep them safe.

API keys let programs use the team's agents and knowledge bases without a browser: the OpenAI-compatible endpoint, the agent chat API, knowledge base search, and uploads. Create them under Team settings → API keys. Admins and owners see every key of the team; others see their own.

Team settings, API keys tab: personal and service keys with their scopes, restrictions, expiry and last use.

Kinds

Personal keyService key
Belongs toYou, in this teamThe team
Who creates itAny memberAdmins and owners
ScopesDepend on your role (below)Any
When you leave the teamRevoked automaticallyKeeps working
ConversationsStored for you, like your chatsStateless: send earlier turns with each request

A service key has a responsible contact, a team member to ask about it, shown in the key list. An admin can change the contact later.

Scopes and restrictions

ScopeAllowsWho can grant it on a personal key
QueryChat with agents and search knowledge basesEveryone
IngestUpload and manage documentsEditors, admins, owners
ManageChange sources and knowledge basesAdmins, owners

A key can also be restricted to some knowledge bases and some agents. Leave them unchecked to allow every knowledge base, or every agent, of the team. A key can have an expiry date; it stops working at the end of that day.

Keys always belong to one team, and can never administer the platform.

Creating one

  1. Team settings → API keys → New API key.
  2. Name it after what will use it ("Course site search"), pick personal or service, the scopes, any restrictions, and optionally an expiry date.
  3. Copy the secret. It's shown once, right after creation; Grounded stores only a keyed hash of it. The dialog also shows an example request.

Keys look like rag_<id>_<secret>. Send them as a bearer token:

curl -H "Authorization: Bearer $GROUNDED_API_KEY" https://grounded.example.org/v1/models

Revoking

Revoke… stops the key at once; programs using it get 401. It can't be undone. Revoked keys stay visible from the audit log, read-only, so the history keeps making sense.

Each key's page shows when it was created and last used. Revoke keys nobody uses. If a key may have leaked, revoke it and create a new one.

When the platform rotates its pepper

Platform operators occasionally rotate the secret used to hash API keys. Keys keep working if they're used during the grace period the operators set. A key that isn't used in that time stops working, and you'll need to create a new one. See Security.

On this page