Skip to main content
Every request to the Runtime Cloud API must include a valid API key. Keys are scoped to a user and optionally to an organization, so the same person can hold keys for personal resources and for each org they belong to.

Bearer token

Pass your key in the Authorization header:
All API keys use the prefix runtm_sk_ followed by an opaque secret. The raw secret is shown once when you create the key - store it in a secrets manager or environment variable immediately.

Creating API keys

1

Open the dashboard

Sign in at app.runtm.com and navigate to Settings > API Keys.
2

Choose context

  • Personal key - created outside any org; sees only your personal sessions, secrets, and instructions.
  • Organization key - switch to an org first, then create the key; it sees that org’s shared resources.
3

Select scopes

Pick a preset (Session automation, Full access, Read-only) or choose individual scopes. See Scopes & Permissions for the full list.
4

Copy the secret

The raw key is displayed once. Copy it now - you cannot retrieve it later. You can always verify a key with the Verify endpoint.

Organization context

For org-scoped operations, include the X-Organization-Id header:
If the key was created in an org context, the organization is already embedded in the key. You can still pass the header explicitly - the API uses it as confirmation and will reject a mismatch. If the key was created in personal context, omitting the header returns your personal resources. Adding the header scopes the request to the specified org (provided you are a member).

Personal vs organization keys

Security best practices

API keys grant programmatic access to your account. Treat them like passwords.
  • Never commit keys to source control. Use environment variables or a secrets manager.
  • Rotate regularly. Delete old keys and create new ones periodically.
  • Use minimal scopes. Grant only the permissions the integration needs. A CI deploy script does not need sessions:terminal.
  • Use separate keys per integration. If one is compromised, you can revoke it without disrupting others.
  • Monitor usage. Check the Activity endpoints for unexpected access patterns.