Account & Security

API keys

Create, rotate and revoke the API keys your code, the l4 CLI and CI jobs use, from Settings in the dashboard.

An API key lets your own code, the l4 CLI or a CI job reach the LevelFour API without a person signing in. Keys live in the dashboard under Settings > API Keys.

Creating, rotating and revoking keys takes the Admin role. Members and roles lists what each role can do.

Create a key

Open API Keys

In the dashboard sidebar, open Settings, then API Keys, and click Create API Key.

Name it and pick its access

Give the key a name that says where it runs, such as CI pipeline or Finance export.

Under Access, pick one:

  • Read-only fetches data and changes nothing.
  • Read & write can also record decisions, such as accepting a saving.

Under Expiration, pick No expiration, 30 days, 60 days or 90 days. A key minted for a short-lived integration should expire.

Save the key

Click Add. The Save Your Key dialog shows the full key once.

Copy the key before you close the dialog. LevelFour never shows it again, and a lost key can only be replaced.

Click I Have Saved This Key when it is stored.

Authentication covers what each access level reaches in the API, the key prefixes, and where the SDKs and the CLI look for a key.

Find a key

The list shows each key's name, the start of its value, its access, its status, when it was last used, when it ends, and who created it.

Search by name, or use the status filter to show Active, Revoked or All keys. A key that shows Never under Last Used has not made a request yet.

Rotate a key

Open the key's row actions and click Rotate Key, then confirm.

Rotating revokes the current key immediately and issues a new one. Anything still sending the old key stops working until you give it the new one.

The new key appears once, the same way a new key does. Save it before closing the dialog.

Revoke a key

Open the key's row actions and click Revoke Key. Type the key's name to confirm, then click Revoke API Key.

From then on, every request that sends the key returns 401 Unauthorized. A revoked key stays in the list under Revoked, and it cannot be turned back on.

Connected Applications

If your organization uses the MCP server, the same page has a Connected Applications tab. It lists the assistants people have connected, such as Claude or Cursor, and lets you close a connection. Approving a connection covers that tab.

Next

On this page

Ask the FinOps Agent about your cloud spend