---
title: "API Keys"
id: "1920"
type: "page"
slug: "tokens"
published_at: "2026-09-30T22:18:20+00:00"
modified_at: "2026-10-01T00:11:02+00:00"
url: "https://xedant.com/agents/test/docs/tokens"
markdown_url: "https://xedant.com/agents/test/docs/tokens.md"
excerpt: "The build pipeline, the viz command-line tool and external models need access to the product…"
---

# API Keys

[https://xedant.com/agents/test/docs/tokens.md](https://xedant.com/agents/test/docs/tokens.md)

The build pipeline, the `viz` command-line tool and external models need access to the product without a person signing in. For that, long-lived **API keys** are issued: they are not tied to a session and live until they are revoked.

An API key is not the same thing as the installation-wide `TEST_AGENT_API_KEY`. That one covers the whole installation and serves the Chrome extension connection, while API keys are issued one at a time and each has its own scope. The owner manages them.

## Creating

A key is issued in the settings — Settings → API tokens. At the moment of creation its value is shown **once**: store it where you keep secrets. Only a fingerprint remains on the server, so a lost value cannot be recovered — the key has to be revoked and a new one issued.

A key has a name, a creation date, and a last-used mark. Together they show which key is used where, and whether it is time to replace it.

## Scopes

A key carries one of two scopes:

- **Read-only** — the key reads everything and may flag builds for review. It can never write.
- **Read and write** — adds the right to create records.

One rule covers every scope: **no key can approve a baseline.** Approval is a human decision, and it stays with the human in the browser. That way an external tool cannot quietly pin a changed page look and pass it off as the norm.

## Where they are used

The key travels in requests as a header in place of the installation-wide key:

```
Authorization: Bearer taj_…
```

Most often it is needed in three places:

- The build pipeline — sends this header to `/api/ext` instead of `X-API-Key`.
- The `viz` tool — reads the key from the `TEST_AGENT_API_KEY` environment variable and prefers an API key to the installation-wide one.
- The MCP server of the visual tools — accepts the same key.

The scripts family of addresses is available to the same keys as the rest of the external access: through it, scripts are read, edited, trial-run, and their run journal viewed. And the general rule stays in force: even a successful answer from a classifier script approves nothing — the decision always belongs to a human.

What exactly is available at those addresses is described in [External API Access](/agents/test/docs/external-api)
.

## Revoking

A key is revoked instantly: every client using it stops passing authentication at once. The key’s row stays in the list as a trace — you can see the key existed, when it was issued, and when it was revoked.

Next: how to tune the visual checks for your project — in [Visual Testing Settings](/agents/test/docs/visual-settings)
.

[← Back to the documentation index](/agents/test/docs)
