API keys
Every integration except the GitHub App authenticates with an API key: the GitHub Action, GitLab CI, the CLI, the Claude Code plugin, the Cursor and Gemini CLI hooks and the MCP server.
Create a key
Open API keys in the dashboard, optionally name the key (up to 60 characters, for example the repository or machine it's for) and create it. The key is shown once: copy it into your CI secret store or agent settings right away.
Keys start with dgs_. The dashboard lists each key's name, its first characters, when it was created and when it was last used.
Use a key
Send it as a bearer token:
Authorization: Bearer dgs_...Keep keys out of repositories: use CI secrets (DAGSEC_API_KEY) and user-level agent settings.
Revoke a key
Revoke it from the same page. Integrations using it stop working immediately. Create a new key and update the secret.
Limits
- Up to 20 keys per account.
- dagsec stores only a SHA-256 hash of each key, so a lost key can't be shown again; revoke it and create another.
- All of an account's keys share its plan's monthly limits. See Plans and limits.