> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lupin.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# API keys

> Scoped keys, permissions, browser credentials and AgentID.

# API keys

`GET|POST /v0/api-keys` · `DELETE /v0/api-keys/:id`, with project- and
inbox-scoped twins. See [Authentication](/authentication) for scopes and the
permission gate.

## Browser credentials

`POST /v0/emails/inboxes/:inbox_id/browser-credentials/enrollments` starts an
enrollment and activates a credential; list at
`GET /v0/api-keys/browser-credentials`, revoke with
`DELETE …/browser-credentials/:credential_id`, cancel enrollments at
`DELETE …/browser-credentials/enrollments/:enrollment_id`. Lifecycle events:
`GET …/browser-credentials/events`. Consents live under
`/v0/api-keys/browser-consents…`.

## AgentID public keys

Register a JWK-bound credential:

```bash theme={null}
curl -X POST $BASE/v0/api-keys/public-keys -H "authorization: Bearer $KEY" \
  -H 'content-type: application/json' \
  -d '{"name":"agentid","jwk":{"kty":"OKP","crv":"Ed25519","x":"…"}}'
```

Rename with `PATCH …/:id`, revoke one with `DELETE …/:id`, revoke all
sign-in keys with `POST …/agentid-sign-in/revoke-all`. Reads never return key
material.
