Stub — expanding
API SHAPESAPI keys & rotation
The runbook is short because the mechanism is simple: two active keys per workspace, immediate revocation, prefixes that tell you what you’re holding.
WHAT EXISTS TODAY
→Two active keys per workspace — mint, deploy, revoke, in that order→Revocation is immediate; in-flight requests finish→rii_test_ keys never write to production links
Authentication in the reference→ API · Authentication
The header, the prefixes, and the 401 you get when rotation goes wrong.