docs/en/platform/account/api-keys.md
Ultralytics Platform API keys enable secure programmatic access for remote training, inference, and automation. Create named keys with AES-256-GCM encryption for different use cases.
<!-- screenshot -->
!!! note "Owner-Only"
Only the workspace owner can create, view, or revoke a workspace's API keys, because a key authenticates as the
workspace owner. Members with any other role see a note on the tab instead of the key list. API keys themselves
cannot create or revoke other API keys. The one exception is [On Premise worker keys](#on-premise-worker-keys),
which are revoked by disconnecting the host from the On Premise integration.
Create a new API key:
<!-- screenshot -->
Give your key a descriptive name:
training-server - For remote training machinesci-pipeline - For CI/CD integrationlocal-dev - For local developmentAfter creation, the key is displayed in a confirmation dialog:
<!-- screenshot --> !!! tip "Copy Your Key"
Copy your key after creation for easy reference. Keys are also visible in the key list — the platform decrypts and
displays full key values so you can copy them anytime.
API keys follow this format:
ul_a1b2c3d4e5f60718293a4b5c6d7e8f90a1b2c3d4
ul_ identifies Ultralytics keysul_ plus 8 hex characters) act as a display prefix, so a key can be identified without exposing itSet your key as an environment variable:
=== "Linux/macOS"
```bash
export ULTRALYTICS_API_KEY="YOUR_API_KEY"
```
=== "Windows"
```powershell
$env:ULTRALYTICS_API_KEY = "YOUR_API_KEY"
```
Validate and save the key using the YOLO CLI:
yolo login YOUR_API_KEY
Remove the saved key with yolo logout.
Include the key in API requests:
curl -H "Authorization: Bearer YOUR_API_KEY" \
https://platform.ultralytics.com/api/...
Or pass it to the Python SDK (pip install "ultralytics-platform>=0.1.5"), which also reads ULTRALYTICS_API_KEY:
from ultralytics_platform import Platform
client = Platform(api_key="YOUR_API_KEY")
See the REST API Reference for all available endpoints.
Enable metric streaming with your key.
Install or update the Ultralytics package before starting:
pip install -U ultralytics
export ULTRALYTICS_API_KEY="YOUR_API_KEY"
yolo train model=yolo26n.pt data=coco.yaml project=username/project name=exp1
See Cloud Training for the complete remote training guide.
All keys are listed on the Settings > API Keys tab:
Each key card shows the key name, the copyable key value, the relative creation time, and a revoke button.
Revoke a key that's compromised or no longer needed:
!!! warning "Immediate Effect"
Revocation is immediate and permanent — the key record is deleted, not disabled. Any applications using the key
will stop working.
If a key is compromised:
API keys are scoped to the currently active workspace:
When switching workspaces in the sidebar, the API Keys section shows keys for that workspace. Because a workspace key carries owner permissions, only the workspace owner can create, view, or revoke one. See Teams for role details.
Connecting an On Premise host mints a separate worker key. Worker keys are managed from the On Premise integration rather than this tab, are never listed alongside your API keys, and are revoked by disconnecting the host — which also cancels that host's queued and running jobs.
Rotate keys periodically for security:
!!! tip "Rotation Schedule"
Consider rotating keys every 90 days for sensitive applications.
Error: Invalid API key
Solutions:
ul_ prefix)ultralytics>=8.4.120Error: Permission denied for this operation
Solutions:
Workspace owner access requiredError: Rate limit exceeded
Solutions:
Retry-After headerThere's no hard limit on API keys. Create as many as needed for different applications and environments.
Keys don't expire automatically. They remain valid until revoked. Consider implementing rotation for security.
Yes, full key values are visible in the key list on Settings > API Keys. The Platform decrypts and displays your keys so you can copy them anytime.
Keys work across regions but access data in your account's region only.
No — a team workspace key authenticates as the workspace owner, so only the owner can create or view one, and sharing it hands over owner permissions. Have each member create a key in their own personal workspace instead, and ask the owner to mint a dedicated workspace key for shared automation such as CI.
No. A key belongs to the workspace it was created in and only reaches that workspace's resources. Create a separate key for each workspace you automate.