
Create a management key in the xAI Console
Mint a management key in the xAI Console when you need to call https://management-api.x.ai for team admin work instead of clicking through every Console screen by hand. Official Using Management API and the Management REST API Overview separate this secret from inference API keys: the management host is different, the key lives under Settings → Management Keys, and your user on the team Users page needs Management Keys Read + Write before the create controls appear. Collections docs add the concrete create flow and warn that you must copy the secret immediately because the Console will not show it again. Start at console.x.ai on the team that should own the key.
What you need
A Console login on the correct team in the team picker, Management Keys Read + Write on your account (ask a team admin on the Users page if the Settings entry is missing), and a plan for which Management API permissions the key should carry. Collections upload needs AddFileToCollection; broader collection create, update, and delete work needs the matching Collections Endpoint group permissions when you enable them on create. Store the secret in a password manager or environment variable the same way you treat an inference key. After you have the key, validate it and manage inference keys with Manage API keys with the xAI Management API, pull audit events with List audit events via the xAI Management API, and watch prepaid balance with Check prepaid credit balance via the xAI Management API. More API jobs live on the API hub.
Create the key and copy it once
- Sign in to console.x.ai and confirm the team picker shows the team that should own the management key before you open any Settings screen.
- Open the Users page and confirm your account has Management Keys Read + Write; if those options are missing, ask a team admin to enable the permissions before you continue.
- Open Settings → Management Keys (the Management Keys section in the Console) and click Create Management Key.
- Select the permissions this key needs: for Collections document upload include
AddFileToCollection, and for create, update, or delete on collections enable the corresponding permissions in the Collections Endpoint group along with any other Management API scopes you actually use. - Finish create, then copy the management key immediately into your secret store, because official docs warn you will not be able to view the full secret again after you leave the page.
Base URL for every Management API call is https://management-api.x.ai, so do not send this Bearer token to https://api.x.ai and do not use an inference API key on management routes.
Prove the key works
Run the validation endpoint with no special ACL requirements when you only need to confirm the secret and read its meta:
curl https://management-api.x.ai/auth/management-keys/validation \
-H "Authorization: Bearer <Your Management API Key>"
A successful response returns key id, scope, owner, name, and ACL list. Keep that output out of chat transcripts and public tickets. When the job is Collections upload rather than key admin, follow Upload a document to a collection after the key has AddFileToCollection.
Pitfalls
Creating the key on the wrong team in the picker binds admin power to the wrong billing and membership boundary, while skipping Management Keys Read + Write on the Users page leaves Settings empty even though the account can sign in. Leaving the create dialog without copying the secret forces you to mint another key because the Console will not redisplay the full value. Granting every Collections and admin ACL “just in case” widens blast radius when the secret leaks, so prefer the smallest permission set that matches the job. Using the management key as an inference Bearer against api.x.ai fails and confuses monitoring that expects separate key classes.