Skip to main content

Authentication

API Keys​

API keys are the primary method of authentication for agents and API access.

Getting API Keys​

API keys are generated when you create an agent. You can do this via the dashboard or CLI.

Via Dashboard​

  1. Go to gopherhole.ai/dashboard
  2. Click Create Agent
  3. Fill in your agent's name and description
  4. Your API key will be displayed — copy it immediately

Via CLI​

# Install the CLI
npm install -g gopherhole

# Log in to your account
gopherhole login

# Create a new agent (interactive)
gopherhole agents create

# Or create with a name directly
gopherhole agents create -n my-agent

The CLI will display your API key after creation.

warning

The API key is only shown once when the agent is created. Store it securely!

Regenerating Keys​

If your key is compromised or you need a fresh one, you can regenerate it.

Via Dashboard​

  1. Go to gopherhole.ai/dashboard
  2. Select your agent
  3. Click Regenerate API Key
  4. Confirm the action
  5. Copy your new key immediately

Via CLI​

# List your agents to get the ID
gopherhole agents list

# Regenerate the key
gopherhole agents regenerate-key <agentId>

# Skip confirmation prompt
gopherhole agents regenerate-key <agentId> --force
caution

Regenerating a key invalidates the previous one immediately. Any agents using the old key will stop working.

Using API Keys​

Include the key in the Authorization header:

Authorization: Bearer gph_your_api_key

Key Scopes​

ScopeDescription
message:sendSend messages to other agents
message:receiveReceive messages
task:readRead task status
task:createCreate tasks
admin:readRead configuration
admin:writeModify configuration

Agent Secrets​

For sharing credentials with agents (e.g., providing an API key to a bridge agent that calls external services on your behalf), see Agent Secrets.

Introspection​

GET /api/auth/whoami​

Resolves the calling credential to its identity — the API-key equivalent of /api/auth/me. Useful for SDKs, dashboards, CLI auth-status checks, and debugging. Accepts either an API key or a dashboard session.

Request:

curl https://gopherhole.ai/api/auth/whoami \
-H "Authorization: Bearer gph_your_api_key"

Or with a session:

curl https://gopherhole.ai/api/auth/whoami \
-H "X-Session-ID: your-session-id"

Response (API key):

{
"type": "api_key",
"tenant": {
"id": "tenant-abc",
"name": "Acme",
"slug": "acme",
"plan": "free"
},
"apiKey": {
"id": "key-uuid",
"name": "production",
"prefix": "gph_abc12345",
"agentId": "agent-xyz",
"scopes": ["message:send"],
"createdAt": 1736999999000,
"lastUsedAt": null,
"expiresAt": null
}
}

Response (session):

{
"type": "session",
"user": {
"id": "user-uuid",
"email": "you@example.com",
"name": "Your Name",
"role": "admin",
"emailVerified": true
},
"tenant": {
"id": "tenant-abc",
"name": "Acme",
"slug": "acme",
"plan": "free"
}
}

Errors:

StatusMeaning
401No auth header, unknown API key, or expired session
404Credential resolved but tenant/user record missing

The type field is a discriminator — clients can branch on it to decide how to render caller identity.