Sessions & API Keys

Sign out of JARVIS, understand how sessions behave, and create or revoke personal API keys.

Two kinds of credential give access to your JARVIS account: browser sessions and personal API keys. This page covers both.

Sessions

Signing in creates a session for your account on that device. JARVIS keeps you signed in for 30 days.

Signing out

Settings → Account → Sign out ends the session on the current device and returns you to the sign-in page. Other devices stay signed in.

Ending every session

Changing your password ends all sessions on all devices. See Password & Recovery.

What JARVIS does not do

  • It does not send session tokens in replies, exports, or logs you can reach.
  • It does not let you view or replay an active session token.
  • A revoked or expired session cannot be renewed — you sign in again.

If you think someone else is using your account, change your password. That is the fastest way to lock them out.

API keys

An API key lets your own code talk to JARVIS as you. Create and manage keys at jarvis.spacekeep.dev/developer.

Creating a key

  1. Open the Developer page.
  2. Enter a name — something that says where the key is used, like laptop or ci.
  3. Choose Create key.

The full key appears once, with a Copy button. Copy it immediately: only a hash is stored, so the key itself cannot be shown again.

Keys begin with jrv_.

Using a key

Send it as a bearer token:

curl -s https://jarvis.spacekeep.dev/api/jarvis/chat \
  -H "Authorization: Bearer $JARVIS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"message":"What did I ask you to remember?"}'

Keys work with chat, conversations, and tasks. They are not accepted by the memory, web activity, or key management endpoints — those are session-only.

Key list

Each key shows its name, a short prefix, when it was created, and when it was last used. A key that has never been called says never used — a good signal that it is either unnecessary or misconfigured.

Revoking a key

Revoke, then Confirm revoke. The key stops working on its next request.

Create a replacement key before revoking, if something depends on it.

Keeping keys safe

  • One key per tool. It makes revocation surgical.
  • Never commit a key to source control — read it from an environment variable.
  • Give a key the smallest useful lifetime: revoke it when the tool is retired.
  • Revoke any key you did not create yourself, or cannot explain.
  • JARVIS will never ask for a key in a conversation, and keys are never returned by any endpoint after creation.