
Keys are bearer tokens for api.mails.ai. A key is shown in full exactly once, at creation; after that only its prefix is visible, because we store a hash and genuinely cannot recover it for you.

mk_live_... — real sends, real billing.
mk_test_... — the full path, nothing transmitted, never billed.
A key can be limited to send, to read, or to a single agent. A key scoped to one agent cannot send as any other, which is what you want for the service that only ever sends receipts. Keys are capped per plan: 10 on Free, 50 on Pro, 200 on Scale.
Create the new key.
Deploy it.
Watch Last used on the old key until it stops moving.
Revoke the old key.
Revoking is immediate and cannot be undone. If a key has leaked, revoke first and reorder those steps — a few failed requests are cheaper than an open door.
Manage API keys