> ## Documentation Index
> Fetch the complete documentation index at: https://docs.alakazam.gg/llms.txt
> Use this file to discover all available pages before exploring further.

# Mint a long-lived API key

> Create a `forge_sk_…` key for the calling account. A login token expires in about an hour and, for a Google/Apple account, can only be renewed through an email round-trip — an API key does not expire, so it is the credential for MCP clients, CI, and partner integrations. **The raw key is returned in this response and never again**: only a SHA-256 hash is stored, so a lost key must be revoked and replaced. Max 20 keys per account (429 over). Requires an existing authenticated session (a JWT, or another API key).




## OpenAPI

````yaml /forge-api-v1.yaml post /api/workbench/api_keys
openapi: 3.0.3
info:
  title: Alakazam Forge API
  version: '1.0'
  description: |
    The Forge Dataset Workbench API: upload or import robotics datasets,
    audit them, propose and run augmentation campaigns, review, and deliver.
    Served by the Forge workbench service at forge.alakazam.gg (not
    api.alakazam.gg).
servers:
  - url: https://forge.alakazam.gg
    description: Forge (Dataset Workbench)
security: []
tags:
  - name: Dataset Workbench
    description: |
      **Served at `https://forge.alakazam.gg`** (not the main API host). The
      Forge Dataset Workbench is the client surface of the robotics
      data-augmentation service: bring a LeRobot robot dataset, a public
      Hugging Face repo, a resumable chunked upload, or a one-click curated
      sample, and walk one owner-scoped **campaign** through the spine
      Source & Health → Sample → Transform → Run + Verify → Deliver, leaving
      with a verified augmented dataset. Every endpoint requires a **Supabase
      user access token** (`Authorization: Bearer …`, the `UserAuth` scheme);
      a missing or invalid token returns `401`, and another user's campaigns,
      runs, and uploads read as `404`. Errors use the platform envelope
      `{"detail": "…"}`. Nothing bills until **Deliver**, which charges 1
      credit per never-before-billed kept episode from your credits wallet.
  - name: Playground batches
    description: |
      The Forge playground's "describe a change" flow is not a REST surface on
      this host: a described change is submitted as a **scenario batch**
      through the platform (the Supabase RPC `create_scenario_batch`) and its
      progress/results stream back over Supabase realtime on the
      `scenario_batches` table. For the equivalent public REST surface, see
      **Scenario Studio** (`/v1/scenario-batches`).
paths:
  /api/workbench/api_keys:
    servers:
      - url: https://forge.alakazam.gg
        description: Forge (Dataset Workbench)
    post:
      tags:
        - Dataset Workbench
      summary: Mint a long-lived API key
      description: >
        Create a `forge_sk_…` key for the calling account. A login token expires
        in about an hour and, for a Google/Apple account, can only be renewed
        through an email round-trip — an API key does not expire, so it is the
        credential for MCP clients, CI, and partner integrations. **The raw key
        is returned in this response and never again**: only a SHA-256 hash is
        stored, so a lost key must be revoked and replaced. Max 20 keys per
        account (429 over). Requires an existing authenticated session (a JWT,
        or another API key).
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                label:
                  type: string
                  description: >-
                    Human label so the key is identifiable later, e.g.
                    "ci-pipeline". Max 80 chars.
      responses:
        '200':
          description: Minted. `key` is the ONLY copy.
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  label:
                    type: string
                  masked:
                    type: string
                    description: e.g. `forge_sk_…a1b2`
                  created_at:
                    type: string
                  key:
                    type: string
                    description: The raw key. Shown once, never recoverable.
                  warning:
                    type: string
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Key limit reached — revoke one first.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Key store not configured (durable storage unavailable).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - UserAuth: []
components:
  schemas:
    Error:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable error message.
        errors:
          type: array
          items:
            type: string
          description: Field-level validation errors (e.g. on 422 from POST /v1/worlds).
        schemaVersion:
          type: string
      required:
        - detail
  securitySchemes:
    UserAuth:
      type: http
      scheme: bearer
      description: >
        Either a Supabase user access token (from a password login, or the
        passwordless magic-link flow) or a long-lived `forge_sk_…` API key. Both
        are sent as `Authorization: Bearer <value>` and resolve to the same
        owner, so every endpoint accepts either. Session tokens expire in ~1h;
        API keys do not expire and are the credential for MCP clients, CI, and
        partner integrations.

````