Documentation / Manage ingest keys

Manage ingest keys

An ingest key lets a gateway, collector or SDK send usage to Meridian. It carries the meridian:ingest scope and nothing else: it can write events, gateway logs and capacity metrics, and it can't read data back. Organization admins create and revoke these keys in Meridian settings.

Who can manage keys

Organization owners and admins. Other members who open the page see a notice instead of the key list, and the API returns 403 for them.

Create a key

  1. In Meridian, open Settings → Ingest keys.
  2. Enter a name for the producer that will use the key, for example "LiteLLM production" or "DCGM Prometheus".
  3. Select Create key. The key appears once, in a dialog. Select Copy key and store it in your secret manager before closing the dialog. Meridian keeps only a hash, so a lost key can't be shown again; revoke it and create another.

Every key gets the same limits: 600 requests per minute and 100,000 requests per day, with no expiry date. An organization can have up to 10 active ingest keys; past that, creating a key returns an error until you revoke one. Use one key per producer (each proxy, collector, staging environment or SDK) so revoking one doesn't stop the others.

What the list shows

  • Name and the key prefix, so you can match a key to the value in your secret manager without seeing the secret.
  • Scope: always meridian:ingest.
  • Created by and Created: the admin who made the key and when.
  • Last used: the last request made with the key, or Never.
  • Status: Active, Revoked or Expired.

Revoke a key

Select Revoke on the key and confirm. Revocation applies from the next request: anything still sending with the key gets 401 "API key has been revoked" and its data stops reaching Meridian. Revoked keys stay in the list for the record and can't be reactivated.

To rotate a key, create the new key, update the producer, confirm data is arriving (the Last used time on the new key moves), then revoke the old key.

Ingest keys and Event ingest keys

The keys on the Event ingest settings page are integration keys for discovery events. They are a different kind of key and the gateway, capacity and OASA event endpoints reject them with 401. Use an ingest key from this page for those endpoints.

Where keys are used

Rate limits, monthly event allowances and producer health are covered in Event allowances and rate limits.

API reference

The settings page uses these endpoints on https://api.onaro.io. They take a signed-in Meridian session, not an API key, and return 403 unless the caller is an organization owner or admin.

GET /api/meridian/ingest-keys

Lists the organization's ingest keys, newest first. Secrets are never returned.

{
  "keys": [
    {
      "id": "6f1c…",
      "name": "LiteLLM production",
      "scope": "meridian:ingest",
      "key_prefix": "bai_live_AbCdEfG...wxyz",
      "created_by": "admin@example.com",
      "created_at": "2026-10-07T14:02:11+00:00",
      "last_used_at": "2026-10-07T15:40:02+00:00",
      "revoked_at": null,
      "status": "active"
    }
  ]
}

POST /api/meridian/ingest-keys

Body {"name": "Kong production"} (1 to 200 characters). Returns 201 with the same fields as a list entry plus key_secret, which is returned only in this response.

  • 409 when the organization already has 10 active ingest keys. detail.code is ingest_key_limit_reached, with active, limit and message.
  • 422 when the name is missing or blank.

POST /api/meridian/ingest-keys/{id}/revoke

Revokes the key and returns it with status: "revoked". Returns 404 when the key doesn't belong to your organization, isn't an ingest key, or is already revoked.