> ## Documentation Index
> Fetch the complete documentation index at: https://cadenya.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the global API key

> The account's system-provisioned key, the one credential that works in every workspace.

Every account gets exactly one global key, created by the system. It spans all workspaces, cannot be deleted, and lives on the account rather than in any [workspace key list](/docs/api-reference/apikeyservice/list-api-keys). This endpoint takes no ID because there is nothing to choose.

<CodeGroup>
  ```typescript TypeScript theme={null}
  const key = await client.globalAPIKey.retrieve();

  console.log(key.spec.system); // true
  console.log(key.state);       // STATE_ENABLED
  ```

  ```go Go theme={null}
  key, err := client.GlobalAPIKey.Get(ctx)
  if err != nil {
  	log.Fatal(err)
  }

  log.Println(key.Spec.System) // true
  log.Println(key.State)       // STATE_ENABLED
  ```

  ```ruby Ruby theme={null}
  key = cadenya.global_api_key.retrieve

  puts key.spec.system # true
  puts key.state       # STATE_ENABLED
  ```

  ```bash cURL theme={null}
  curl "https://api.cadenya.com/v1/account/global_api_key" \
    -H "Authorization: Bearer ${CADENYA_API_KEY}"
  ```
</CodeGroup>

## The token comes back only to a stronger caller

Unlike workspace keys, this read can include `spec.token`, but only when the calling key's scopes dominate the global key's. A narrowly scoped caller gets the key without the token. That closes the loophole where a weak key reads the strong key's credential and promotes itself; the rule is the same one covered in [managing keys with keys](/docs/guides/api-key-scopes#managing-keys-with-keys).

## Treat it as the break-glass credential

The global key holds full access across every workspace, which makes it the right bootstrap credential and the wrong daily driver. Mint [workspace keys](/docs/api-reference/apikeyservice/create-a-new-api-key) with narrow scopes for services, and keep the global key for provisioning and recovery. If its exposure ever worries you, the [kill switch](/docs/api-reference/globalapikeyservice/disable-the-global-api-key) works while you [rotate](/docs/api-reference/globalapikeyservice/rotate-the-global-api-key).

## Related

<CardGroup cols={2}>
  <Card title="Rotate the global key" icon="rotate" href="/docs/api-reference/globalapikeyservice/rotate-the-global-api-key">
    New token, all previous ones invalidated.
  </Card>

  <Card title="Disable the global key" icon="ban" href="/docs/api-reference/globalapikeyservice/disable-the-global-api-key">
    The account-wide kill switch.
  </Card>

  <Card title="Create an API key" icon="key" href="/docs/api-reference/apikeyservice/create-a-new-api-key">
    The scoped keys you should be using instead.
  </Card>

  <Card title="API key scopes" icon="shield-check" href="/docs/guides/api-key-scopes">
    What scope dominance means, precisely.
  </Card>
</CardGroup>


## OpenAPI

````yaml get /v1/account/global_api_key
openapi: 3.1.0
info:
  title: Cadenya API
  description: API for the Cadenya Agent Runtime platform.
  version: '1.0'
servers:
  - url: https://api.cadenya.com
    description: Production server
security:
  - bearerAuth: []
tags:
  - name: AIProviderKeyService
  - name: APIKeyService
    description: |-
      Issue, rotate, disable, and revoke a workspace's API keys. Every key
       belongs to exactly one workspace; the system-managed global account key is
       managed via GlobalAPIKeyService instead.
  - name: AccountService
    description: >-
      Manage the authenticated account. Accounts are the top-level
      organizational
       unit and contain one or more workspaces.
  - name: AgentScheduleService
    description: >-
      Manage recurring schedules attached to agents. Schedules trigger
      objectives
       on a cadence defined by AgentScheduleSpec.Schedule.
  - name: AgentService
    description: >-
      Manage AI agents within a workspace. Agents define AI behavior and tool
      access.
  - name: AgentVariationService
    description: >-
      Manage variations of an agent and their tool, sub-agent, and memory layer
      assignments.
  - name: GlobalAPIKeyService
    description: |-
      Manage the account's system-provisioned global API key. The global key is
       the only key that spans every workspace; it is created by the system and
       cannot be deleted, so the surface is retrieve, rotate, and the
       disable/enable kill switch.
  - name: MemoryService
    description: >-
      Manage memory layers and their entries. Layers are named containers that
      can
       be composed into an objective's memory cascade; entries are the keyed values
       within a layer. System-managed layers (e.g., episodic layers created by the
       runtime) cannot be mutated through this API.
  - name: ModelService
    description: |-
      Manage LLM models available to a workspace. Models represent provider and
       family pairs (e.g., "anthropic/claude-sonnet-4.6"). Workspaces are seeded
       with the supported models and you can enable or disable each one.
  - name: ObjectiveEventStreamsService
  - name: ObjectiveService
  - name: ProfilesService
    description: |-
      Operations on profiles, the account-level principals (users, API keys,
       system) that authenticate against the API.
  - name: SearchService
  - name: TenantService
    description: >-
      Read and erase tenants and the subjects under them. Tenants and subjects
      are
       created by assertion — on objective creation or widget session mint — never
       directly, so this service has no create or update: it exists to enumerate what
       assertions have produced, and to destroy it on request.
  - name: ToolService
    description: >-
      Manage tool sets and the tools they contain. Tool sets group related
      tools,
       and tools define specific capabilities available to agents.

       When a tool set is managed, only API key actors can modify its tools; human
       (profile) actors cannot.
  - name: UploadService
    description: |-
      Issue short-lived presigned URLs for direct client-to-object-storage
       uploads. Created uploads can be referenced by id when creating or updating
       resources that accept binary content (e.g., MemoryEntry).
  - name: WidgetService
    description: |-
      Manage embeddable chat widgets. A widget binds an agent to a globally
       unique hostname with a per-widget origin allowlist; browsers reach it with
       session tokens minted via WidgetSessionService.
  - name: WidgetSessionService
    description: >-
      Mint and manage widget sessions. Session creation is server-to-server
      only:
       the customer's backend authenticates its visitor, asserts tenant/subject
       context, attaches any per-visitor secrets, and receives a short-lived
       bearer token the browser uses against the widget host.
  - name: WorkspaceAdminService
    description: >-
      Administer workspaces across the account: create and archive workspaces
      and
       manage their membership. These operations are account-scoped and require the
       admin role (a token whose profile holds the WorkOS admin role); they live
       under /v1/account/workspaces rather than the workspace-scoped /v1/workspaces
       tree so an admin can manage any workspace in the account, including ones they
       are not themselves a member of.
  - name: WorkspaceSecretService
  - name: WorkspaceService
    description: |-
      Manage workspaces within an account. Workspaces provide organizational
       grouping and isolation for resources such as agents, tools, and API keys.

       This is the workspace-scoped, end-user surface. Administrative operations
       (create / archive workspaces, manage members) live in WorkspaceAdminService
       under /v1/account/workspaces and require the admin role.
paths:
  /v1/account/global_api_key:
    get:
      tags:
        - GlobalAPIKeyService
        - API Keys
      summary: Get the global API key
      description: >-
        Retrieves the account's global API key. The token is included only when
        the caller's scopes dominate the key's.
      operationId: GlobalAPIKeyService_GetGlobalAPIKey
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKey'
        default:
          description: Default error response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Status'
      x-codeSamples:
        - lang: JavaScript
          source: |-
            import Cadenya from '@cadenya/cadenya';

            const client = new Cadenya({
              apiKey: process.env['CADENYA_API_KEY'], // This is the default and can be omitted
            });

            const apiKey = await client.globalAPIKey.retrieve();

            console.log(apiKey.metadata);
        - lang: Python
          source: |-
            import os
            from cadenya import Cadenya

            client = Cadenya(
                api_key=os.environ.get("CADENYA_API_KEY"),  # This is the default and can be omitted
            )
            api_key = client.global_api_key.retrieve()
            print(api_key.metadata)
        - lang: Go
          source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"go.cadenya.com/cadenya-go\"\n\t\"go.cadenya.com/cadenya-go/option\"\n)\n\nfunc main() {\n\tclient := cadenya.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\tapiKey, err := client.GlobalAPIKey.Get(context.TODO())\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", apiKey.Metadata)\n}\n"
        - lang: Ruby
          source: |-
            require "cadenya"

            cadenya = Cadenya::Client.new(api_key: "My API Key")

            api_key = cadenya.global_api_key.retrieve

            puts(api_key)
        - lang: CLI
          source: |-
            cadenya global-api-key retrieve \
              --api-key 'My API Key'
components:
  schemas:
    APIKey:
      required:
        - metadata
        - spec
        - state
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/AccountResourceMetadata'
        spec:
          $ref: '#/components/schemas/APIKeySpec'
        info:
          $ref: '#/components/schemas/APIKeyInfo'
        state:
          readOnly: true
          enum:
            - STATE_UNSPECIFIED
            - STATE_ENABLED
            - STATE_DISABLED
          type: string
          description: |-
            The current lifecycle state of the API key. Output only. Keys are
             created STATE_ENABLED; use the :disable and :enable actions to
             transition between states.
          format: enum
      description: >-
        An API key. Every key belongs to exactly one workspace and is managed
        via
         the workspace-scoped API key routes. The only exception is the
         system-managed global account key, which spans all workspaces and is
         managed via the account global_api_key routes.
    Status:
      type: object
      properties:
        code:
          type: integer
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
          format: int32
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/GoogleProtobufAny'
          description: >-
            A list of messages that carry the error details.  There is a common
            set of message types for APIs to use.
      description: >-
        The `Status` type defines a logical error model that is suitable for
        different programming environments, including REST APIs and RPC APIs. It
        is used by [gRPC](https://github.com/grpc). Each `Status` message
        contains three pieces of data: error code, error message, and error
        details. You can find out more about this error model and how to work
        with it in the [API Design
        Guide](https://cloud.google.com/apis/design/errors).
    AccountResourceMetadata:
      required:
        - id
        - accountId
        - name
        - profileId
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the resource (prefixed ULID, e.g.,
            "apikey_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this resource belongs to for multi-tenant isolation
            (prefixed ULID)
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
             Required for resources that users interact with directly
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
        createdAt:
          readOnly: true
          type: string
          format: date-time
      description: >-
        AccountResourceMetadata is used to represent a resource that is
        associated to an account but not to a workspace.
    APIKeySpec:
      type: object
      properties:
        token:
          readOnly: true
          type: string
          description: >-
            The bearer token used to authenticate as this API key. Returned only
            on
             creation and rotation; subsequent reads omit this field.
        description:
          type: string
          description: Free-form description of what this API key is used for.
        permissions:
          type: array
          items:
            type: string
          description: |-
            Scopes granted to this key. Each entry is a colon-separated
             resource:verb string (e.g. "objectives:manage").

             Resources: agents, objectives, tools, memory, api_keys, workspaces,
             widgets, widget_sessions, secrets, account.
             Verbs: read and manage, where manage implies read — a stored scope set
             is normalized to drop "x:read" when "x:manage" is present. The secrets
             and account resources support only manage. "*" is an explicit
             full-access grant.

             Scopes are deny-by-default: a key with an empty list can call only
             scope-free endpoints. Full access is always an explicit "*" grant.
        system:
          readOnly: true
          type: boolean
          description: >-
            True when this key is managed by the system (i.e. the
            auto-provisioned
             global account key). System keys cannot be deleted but can be rotated.
      description: Configuration for an API key.
    APIKeyInfo:
      type: object
      properties:
        createdBy:
          readOnly: true
          allOf:
            - $ref: '#/components/schemas/Profile'
          description: The profile that created the key.
    GoogleProtobufAny:
      type: object
      properties:
        '@type':
          type: string
          description: The type of the serialized message.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message.
    Profile:
      required:
        - metadata
        - spec
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/AccountResourceMetadata'
        spec:
          $ref: '#/components/schemas/ProfileSpec'
      description: |-
        A profile identifies a user or non-human principal (such as an API key)
         at the account level. Profiles are account-scoped and can be granted access
         to multiple workspaces.
    ProfileSpec:
      required:
        - type
      type: object
      properties:
        email:
          type: string
          description: >-
            Email address of the profile. Required and unique within an account
            for
             user profiles.
        name:
          type: string
          description: Display name (e.g., "Bobby Tables").
        type:
          enum:
            - PROFILE_TYPE_UNSPECIFIED
            - PROFILE_TYPE_USER
            - PROFILE_TYPE_API_KEY
            - PROFILE_TYPE_SYSTEM
          type: string
          description: >-
            Whether this profile represents a human user, an API key, or a
            system
             principal.
          format: enum
      description: Configuration for a profile.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````