- Keys are created in Settings → API — create one per integration so each can be revoked on its own. Unlimited keys.
- The full key is shown once, at creation. pepline stores only a fingerprint; if you lose a key, create a new one.
- Keys are organization-scoped: one key reaches your whole knowledge library, across agents.
- Revoking (the archive action in Settings) cuts access immediately. Restoring a revoked key brings the same key back to life — an accidental revocation is recoverable.
- Treat keys like passwords: server-side only, never in frontend code, never in a repository. The widget’s publishable key is a different, deliberately public credential — don’t confuse the two.
401 with error.code of missing_api_key or invalid_api_key (unknown or revoked).
