# Sessions & API Keys

Two kinds of credential give access to your JARVIS account: browser sessions and personal API
keys. This page covers both.

## Sessions

Signing in creates a session for your account on that device. JARVIS keeps you signed in for 30
days.

### Signing out

**Settings → Account → Sign out** ends the session on the current device and returns you to the
sign-in page. Other devices stay signed in.

### Ending every session

Changing your password ends all sessions on all devices. See
[Password & Recovery](/jarvis/account/password/).

### What JARVIS does not do

- It does not send session tokens in replies, exports, or logs you can reach.
- It does not let you view or replay an active session token.
- A revoked or expired session cannot be renewed — you sign in again.

If you think someone else is using your account, change your password. That is the fastest way to
lock them out.

## API keys {#api-keys}

An API key lets your own code talk to JARVIS as you. Create and manage keys at
[jarvis.spacekeep.dev/developer](https://jarvis.spacekeep.dev/developer).

### Creating a key

1. Open the Developer page.
2. Enter a name — something that says where the key is used, like `laptop` or `ci`.
3. Choose **Create key**.

The full key appears **once**, with a **Copy** button. Copy it immediately: only a hash is stored,
so the key itself cannot be shown again.

Keys begin with `jrv_`.

### Using a key

Send it as a bearer token:

```bash
curl -s https://jarvis.spacekeep.dev/api/jarvis/chat \
  -H "Authorization: Bearer $JARVIS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"message":"What did I ask you to remember?"}'
```

Keys work with [chat, conversations, and tasks](/jarvis/api/authentication/). They are not accepted
by the memory, web activity, or key management endpoints — those are session-only.

### Key list

Each key shows its name, a short prefix, when it was created, and when it was last used. A key that
has never been called says **never used** — a good signal that it is either unnecessary or
misconfigured.

### Revoking a key

**Revoke**, then **Confirm revoke**. The key stops working on its next request.

> [!WARNING]
> Revocation is immediate and cannot be undone. Any script still using that key will start
> receiving `401 Invalid API key.`

Create a replacement key before revoking, if something depends on it.

## Keeping keys safe

- One key per tool. It makes revocation surgical.
- Never commit a key to source control — read it from an environment variable.
- Give a key the smallest useful lifetime: revoke it when the tool is retired.
- Revoke any key you did not create yourself, or cannot explain.
- JARVIS will never ask for a key in a conversation, and keys are never returned by any endpoint
  after creation.

## Related

- [API Authentication](/jarvis/api/authentication/) — how keys and sessions are used on the wire
- [Password & Recovery](/jarvis/account/password/) — resetting a password ends all sessions
- [Security](/jarvis/security/) — credential handling and account protection
