Sessions & API Keys
Two kinds of credential give access to your JARVIS account: browser sessions and personal API keys. This page covers both.
Sessions
Signing in creates a session for your account on that device. JARVIS keeps you signed in for 30 days.
Signing out
Settings → Account → Sign out ends the session on the current device and returns you to the sign-in page. Other devices stay signed in.
Ending every session
Changing your password ends all sessions on all devices. See Password & Recovery.
What JARVIS does not do
- It does not send session tokens in replies, exports, or logs you can reach.
- It does not let you view or replay an active session token.
- A revoked or expired session cannot be renewed — you sign in again.
If you think someone else is using your account, change your password. That is the fastest way to lock them out.
API keys
An API key lets your own code talk to JARVIS as you. Create and manage keys at jarvis.spacekeep.dev/developer.
Creating a key
- Open the Developer page.
- Enter a name — something that says where the key is used, like
laptoporci. - Choose Create key.
The full key appears once, with a Copy button. Copy it immediately: only a hash is stored, so the key itself cannot be shown again.
Keys begin with jrv_.
Using a key
Send it as a bearer token:
curl -s https://jarvis.spacekeep.dev/api/jarvis/chat \
-H "Authorization: Bearer $JARVIS_KEY" \
-H "Content-Type: application/json" \
-d '{"message":"What did I ask you to remember?"}'
Keys work with chat, conversations, and tasks. They are not accepted by the memory, web activity, or key management endpoints — those are session-only.
Key list
Each key shows its name, a short prefix, when it was created, and when it was last used. A key that has never been called says never used — a good signal that it is either unnecessary or misconfigured.
Revoking a key
Revoke, then Confirm revoke. The key stops working on its next request.
Warning
Revocation is immediate and cannot be undone. Any script still using that key will start
receiving 401 Invalid API key.
Create a replacement key before revoking, if something depends on it.
Keeping keys safe
- One key per tool. It makes revocation surgical.
- Never commit a key to source control — read it from an environment variable.
- Give a key the smallest useful lifetime: revoke it when the tool is retired.
- Revoke any key you did not create yourself, or cannot explain.
- JARVIS will never ask for a key in a conversation, and keys are never returned by any endpoint after creation.
Related
- API Authentication — how keys and sessions are used on the wire
- Password & Recovery — resetting a password ends all sessions
- Security — credential handling and account protection