Support

CellCog API Keys Guide

Generate and manage the API keys that authenticate the CellCog Python SDK, plugins, and other agents that delegate work to your CellCog account.


What Are API Keys?

API keys let agents and scripts use CellCog programmatically, without the web interface. They authenticate:

  • OpenClaw agents via the CellCog Python SDK
  • Cursor and Claude Code via the CellCog plugin
  • Other agents via the plugin or the Python SDK directly

An API key acts as you: chats it creates appear in your account and bill your credits.

API Keys vs the Keys Page

These are two different things:

  • API keys (this guide) are CellCog credentials. They let external agents call CellCog. You manage them in your profile.
  • The Keys page under Connectors stores third-party credentials (for example, a Stripe or Apollo key) that your CellCog agents read from their environment while working for you. See the Connectors Guide.

Finding Your API Keys

  1. Open your profile menu in the sidebar
  2. Choose API Keys
  3. Or go directly to cellcog.ai/profile?tab=api-keys

Generating an API Key

  1. Click Generate new key
  2. Name the key (for example, the agent or editor that will use it)
  3. Click Generate key
  4. The key is shown once. Copy it and store it somewhere safe
  5. Confirm that you saved it

⚠️ Important: the full key is only shown at generation time. CellCog stores a hash, never the plaintext, so it cannot be recovered later. If you lose a key, revoke it and generate a new one.

You can hold up to 10 active keys at a time, each with its own name. Give each agent or editor its own key so you can revoke one without disturbing the others.


Using Your API Key

With the CellCog Python SDK

Set CELLCOG_API_KEY as an environment variable:

bash
bash
export CELLCOG_API_KEY="sk_..."

Then use the SDK:

python
python
from cellcog import CellCogClient

client = CellCogClient(agent_provider="openclaw")  # reads CELLCOG_API_KEY from the environment

result = client.create_chat(
    prompt="Research quantum computing advances, with citations",
    chat_mode="agent",       # "agent" | "creative" | "team"
    chat_tier="core",        # "flash" | "core" | "max"; omit for the SDK default
    delivery="send_only",    # return immediately; default blocks until the chat is done
    task_label="research",
)

create_chat() also accepts project_id and agent_role_id (run inside a CellCog project), enable_cowork with cowork_working_directory (work on the user's machine), enable_browse with browser_profile_id (drive the user's Chrome), and enable_tools with tools_selection (use the account's connected tools). Full details are in the OpenClaw Integration Guide.

With Plugins

The CellCog plugin for Cursor, Claude Code, and other Open Plugins hosts uses the same variable. See the Plugin Guide.

Direct API Calls

The Python SDK is the supported client. Custom agents that cannot run Python can integrate directly; the Other Agents page under Connectors, then Delegations, describes that path.


Managing Your API Keys

Each key on the API Keys page shows its name, its masked prefix, when it was created, and when it was last used.

Renaming

Click the rename icon next to a key's name, edit, and confirm. Only the name changes; the key itself stays the same.

Revoking

Click Revoke next to the key and confirm inline. Revocation is immediate: any script or integration using that key stops working on its next request.

Regenerating

Revoked keys cannot be restored. Generate a new key and update the environment variable where the old one was used.


Security Best Practices

  1. Never share an API key in public repositories, chat messages, or emails
  2. Use environment variables to store keys in scripts:
    bash
    bash
    export CELLCOG_API_KEY="sk_your_key_here"
  3. One key per agent or editor, so you can revoke a single integration
  4. Rotate keys periodically: generate a new one, switch the integration over, revoke the old one
  5. Watch "Last used" to spot a key that is active when it should not be

Credit Usage

API key usage consumes credits from your account, exactly like web usage:

  • Each chat creation, message, and AI operation uses credits
  • Credits come from your subscription, top-ups, or Auto-Recharge
  • Any positive credit balance starts a chat in every mode and tier; there is no per-mode minimum

Parallel chats are limited by your balance (each 500 credits of effective balance adds one slot, up to 8). The SDK raises a distinct error for this case; see the OpenClaw Integration Guide.

See the Billing Guide for credit details.


Docs for Agents

If an agent needs to read about CellCog itself, point it at cellcog.ai/llms.txt (the index of the site's agent-readable pages) or cellcog.ai/for-agents. Every support guide also has a markdown version at its URL plus .md, for example https://cellcog.ai/support/api-keys-guide.md.

An agent or connector builder that integrates against the API directly (rather than through the Python SDK) reads the public OpenAPI description at cellcog.ai/openapi.json: the API-key surface only (create a chat, send a follow-up, poll, read the result, list chats, credits, the files hand-off), with the X-API-Key header and the credit-recovery step for a 402.


Frequently Asked Questions

Where do I find my API keys?

Open your profile menu and choose API Keys, or go to cellcog.ai/profile?tab=api-keys.

Can I have multiple API keys?

Yes, up to 10 active keys, each named. Revoke one to make room for another.

I lost my API key. How do I get it back?

You cannot. Revoke it and generate a new one.

Does an API key expire?

No. Keys stay active until you revoke them.

What permissions does an API key have?

Full access to your account, the same as being logged in. It can create chats, send messages, and use the features your account has.

Is there a rate limit?

Usage is governed by credits and by the parallel-chat limit tied to your balance. Both are described above.

Can two companies share one account's API keys?

No. One CellCog account is one organization, one company, and every key bills that account. A second company needs its own account, with an email on that company's domain, and its own keys.


Related Guides