API / validate-a-management-key-via-management-api

API

Validate a management key via the xAI Management API

Confirm a management key is accepted and read its metadata over HTTP before you wire billing, auth, or audit scripts that depend on that Bearer. Official Accounts and Authorization documents GET /auth/management-keys/validation on https://management-api.x.ai. The Management API guide states that a successful validation returns meta information about the management key and that this endpoint does not require Access Control List permissions. Create the management key first with Create a management key in the xAI Console if you do not already have one.

What you need

The management key string you intend to use as Authorization: Bearer, exported outside source control, and a clear check that you are calling the Management host rather than the inference API. Validation succeeds only for management keys; an inference API key will not satisfy this route. Neighboring setup jobs include Create a management key in the xAI Console, List API keys via the xAI Management API, and Manage API keys with the xAI Management API. More API jobs live on the API hub.

Validate the key

  1. Export the management key outside of source control:
export XAI_MANAGEMENT_KEY="your_management_key"
  1. Call the validation endpoint:
curl "https://management-api.x.ai/auth/management-keys/validation" \
  -H "Authorization: Bearer ${XAI_MANAGEMENT_KEY}"
  1. On success, read the returned metadata. Documented fields include apiKeyId, scope (SCOPE_TEAM or SCOPE_ORGANIZATION in the docs sample), scopeId, deprecated teamId (prefer scope and scopeId), ownerUserId, createTime, modifyTime, name, acls (management-route permissions such as team-token:endpoint:ListApiKeys), redactedApiKey, and optional ipRanges. Use acls to confirm the key can reach the Management endpoints your runbook needs before you attempt create, list, or billing calls.

  2. Treat a failed validation as a stop. Mint or rotate the management key in Console Settings → Management Keys, re-export the new secret, and validate again before continuing. Do not fall back to placing an inference API key in the Bearer header; Management traffic belongs on https://management-api.x.ai with a management key.

Keep every call on https://management-api.x.ai. An inference API key against https://api.x.ai will not validate as a management key.

Gate scripts on validation

Run validation at the start of CI or operator checklists that later call List API keys via the xAI Management API, billing routes, or audit list. Pair with Create a management key in the xAI Console when a new teammate needs a key with Read + Write Management Keys permission from an admin. Keep Manage API keys with the xAI Management API nearby for the broader key lifecycle after validation passes.

Pitfalls

Validating an inference xai-… secret against this route fails and wastes time debugging ACL strings that never apply to management keys. Logging the full Bearer from the request defeats the point of redactedApiKey in the response. Assuming empty ipRanges means unrestricted access without reading your Console IP policy leaves allowlists unexamined. Calling validation on https://api.x.ai never hits the Management auth surface.