Skip to main content
Backend SDK keys allow your server-side application to log events to Brain on behalf of agents. Each key is scoped to a single project and carries an expiry. The raw key is returned only once in the creation response; after that only the prefix and metadata are stored. Treat the key like a password and store it in a secrets manager or environment variable.
The full SDK key (prefixed otas_...) is shown only in the creation response. It is hashed before storage and cannot be recovered. If you lose the key, revoke it and create a new one.
Only project Admins (privilege=1) can create SDK keys.

Request

Method: POST
URL: http://localhost:8000/api/project/v1/sdk/backend/key/create/
Authentication: X-OTAS-USER-TOKEN + X-OTAS-PROJECT-ID headers

Headers

string
required
Signed JWT for the authenticated user.
string
required
UUID of the project to create the SDK key for.

Body parameters

integer
required
Number of days until the key expires. Must be between 1 and 300.

Response

integer
required
1 on success, 0 on failure.
string
required
backend_sdk_key_created on success.
object

Example

Listing keys

To retrieve a list of all SDK keys for a project (without the raw secret), send:
cURL
The response includes id, prefix, name, created_at, expires_at, active, and revoked_at for each key. Requires Admin privilege.

Revoking a key

To revoke an SDK key immediately, send:
cURL
On success the key’s active flag is set to false and revoked_at is recorded. Requires Admin privilege.

Error responses