> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qumo-deploy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# client.apiKeys

> API keys — project-scoped credentials for relay pub/sub auth.

API keys — project-scoped credentials for relay pub/sub auth.

Reach it as `client.apiKeys` on a [`QumoClient`](/sdk/reference/client#qumoclient).

### list

```ts theme={null}
list(projectId: string): Promise<APIKey[]>
```

Lists a project's API keys. Secrets are never returned.

Types: [`APIKey`](/sdk/reference/types#apikey)

### create

```ts theme={null}
create(projectId: string, params: { name: string; suffix: string; mode: "pub" | "sub"; expires_at?: string }): Promise<{ id: string; secret: string }>
```

Creates an API key. `suffix` narrows the key's broadcast prefix beneath the
project's; `mode` fixes whether its credentials publish or subscribe. The
returned `secret` is shown only once.

### revoke

```ts theme={null}
revoke(projectId: string, keyId: string): Promise<void>
```

Revokes an API key. Credentials already minted keep working until they expire.

### regenerate

```ts theme={null}
regenerate(projectId: string, keyId: string): Promise<{ id: string; secret: string }>
```

Issues a new secret for an API key, invalidating the old one. The new `secret` is shown only once.

### getUsage

```ts theme={null}
getUsage(projectId: string, keyId: string, params: { metric: string; granularity?: "hour" | "day"; start?: string; end?: string }): Promise<APIKeyUsage>
```

Request volume and latency for one API key, bucketed by time and response category.

Types: [`APIKeyUsage`](/sdk/reference/types#apikeyusage)

### listIPAllowlists

```ts theme={null}
listIPAllowlists(projectId: string, keyId: string): Promise<APIKeyIPAllowlist[]>
```

Direct (non-identity) key IP allowlists. A direct key with entries is
restricted to those CIDRs; Identity Tokens are covered by their Identity's allowlist
(ipAllowlists.\*) and return an empty list here. See ADR 0025.

Types: [`APIKeyIPAllowlist`](/sdk/reference/types#apikeyipallowlist)

### createIPAllowlist

```ts theme={null}
createIPAllowlist(projectId: string, keyId: string, cidr: string, label: string): Promise<APIKeyIPAllowlist>
```

Restricts a direct API key to a CIDR range; once any entry exists, other addresses are refused.

Types: [`APIKeyIPAllowlist`](/sdk/reference/types#apikeyipallowlist)

### deleteIPAllowlist

```ts theme={null}
deleteIPAllowlist(projectId: string, keyId: string, allowlistId: string): Promise<void>
```

Removes one IP allowlist entry from a direct API key.
