Bearer token
Pass your key in theAuthorization header:
runtm_sk_ followed by an opaque secret. The raw secret is shown once when you create the key - store it in a secrets manager or environment variable immediately.
Creating API keys
1
Open the dashboard
Sign in at app.runtm.com and navigate to Settings > API Keys.
2
Choose context
- Personal key - created outside any org; sees only your personal sessions, secrets, and instructions.
- Organization key - switch to an org first, then create the key; it sees that org’s shared resources.
3
Select scopes
Pick a preset (Session automation, Full access, Read-only) or choose individual scopes. See Scopes & Permissions for the full list.
4
Copy the secret
The raw key is displayed once. Copy it now - you cannot retrieve it later. You can always verify a key with the Verify endpoint.
Organization context
For org-scoped operations, include theX-Organization-Id header:
Personal vs organization keys
Security best practices
- Never commit keys to source control. Use environment variables or a secrets manager.
- Rotate regularly. Delete old keys and create new ones periodically.
- Use minimal scopes. Grant only the permissions the integration needs. A CI deploy script does not need
sessions:terminal. - Use separate keys per integration. If one is compromised, you can revoke it without disrupting others.
- Monitor usage. Check the Activity endpoints for unexpected access patterns.