---
title: API keys
sidebar_position: 5
---

# API keys

API keys authenticate requests to the Mistral API and other Mistral tools. In Admin, Organization Admins can create, review, rotate, and delete API keys across Workspaces.

Developers can create and manage their own API keys from their User Profile modal in Studio. Vibe-only users usually do not need API keys unless they also use Studio, the API, Vibe Code, or another developer tool.

<SectionTab as="h1" sectionId="key-types">API key types</SectionTab>

API keys can be associated with different product areas:

| Type | Use |
| --- | --- |
| **Studio** | Standard API keys for Mistral API usage. |
| **Vibe** | Keys used by Vibe Code. |
| **Mistral Code** | Legacy keys for earlier Mistral Code usage. |

<SectionTab as="h1" sectionId="create-key-admin">Create an API key as an admin</SectionTab>

1. Open <AppLink href="https://admin.mistral.ai/plateforme/api-keys" path={["Admin Panel", "API", "API Keys"]} />.
2. Select `Create new key`.
3. Optionally enter a `Key name`.
4. Select the `Workspace` the key belongs to.
5. Set an `Expiration` date. If an [API key expiration policy](/admin/identity-access/api-key-policy) applies to the selected Workspace, the date picker only offers dates within the allowed range and the non-expiring option is unavailable. If no policy applies, choose any future date or leave the key non-expiring.
6. Choose the `Connector access scope`.
7. Select `Create new key`.
8. Copy the key immediately.

After you create a key, you cannot change its Workspace, Connector access scope, or expiration date. To change those settings, create a new key and delete the old one.

:::warning
API keys are confidential and are not shared within your Organization. The full key is shown only once. After you close the dialog, you cannot retrieve it. Store it in a password manager or secrets vault. Do not share it or commit it to version control.
:::

<SectionTab as="h1" sectionId="manage-keys">Manage API keys</SectionTab>

Open <AppLink href="https://admin.mistral.ai/plateforme/api-keys" path={["Admin Panel", "API", "API Keys"]} /> to review API keys across the Organization.

The key list shows:

- active and expired keys;
- key type;
- Workspace;
- last used date;
- expiration date.

From the key list, admins can:

- rotate a key by creating a new key and deleting the old one;
- delete a key;
- identify unused or expired keys.

<SectionTab as="h1" sectionId="expiration-policy">API key expiration policy</SectionTab>

An API key expiration policy sets the maximum validity period for newly created API keys. Policies are off by default. Existing keys, including non-expiring keys, keep working until they are revoked or reach their original expiry.

Organization Admins can set an Organization-wide maximum. Workspace Admins can set a stricter Workspace maximum, but they cannot exceed the Organization maximum. Server-side checks enforce active policies for API and UI creation paths.

For policy behavior and hierarchy, see [API key expiration policy](/admin/identity-access/api-key-policy).

<SectionTab as="h1" sectionId="user-profile-keys">Manage your own API keys</SectionTab>

Admins and developers can manage their own API keys from the User Profile modal:

- In Studio, open <AppLink href="https://console.mistral.ai/home?profile_dialog=api-keys" path={["Studio", "API keys"]} />.
- Or open your user profile menu and select `API Keys`.

Use this flow for keys you own. Use the Admin Panel flow when you need to manage keys across the Organization.

:::tip
Admins can also review API keys from a member's `User Details` panel. The `API Keys` tab shows the member's keys, their type, the Workspace each key belongs to, when each key was last used, and when each key expires. See [User management](/admin/identity-access/user-management#api-keys).
:::

<SectionTab as="h1" sectionId="api-key-scope">API key scope</SectionTab>

API keys are scoped to the Workspace where they were created. Requests made with a key use that Workspace's quota, rate limits, and resources.

To use different keys for different environments, such as development, staging, and production, create separate [Workspaces](/admin/workspaces/your-first-workspace) and create a dedicated API key in each Workspace.

Connector access scope controls which Workspace Connectors the key can use.

| Scope | Access |
| --- | --- |
| **Shared connectors only** | Access only Connectors shared with the Workspace, not private Connectors. |
| **Private and shared connectors** | Access both private Connectors owned by the key creator and Connectors shared with the Workspace. |

The default scope is `Shared connectors only`. Use it for automation. Choose `Private and shared connectors` only when the application needs private Connectors owned by the key creator.

For Connector administration, see [Connectors](/admin/identity-access/connectors).

:::note
API keys are not scoped to plans. You cannot create a Free mode API key or a pay-as-you-go API key. Each key automatically uses your Organization's Mistral plan and pay-as-you-go settings. See [Subscriptions](/admin/billing-usage/subscriptions).
:::