A key is arena_sk_ followed by 43 base64url characters (256 bits). It belongs to one Google or Apple account and acts on that real Arena account. New keys default to read scopes; add trade:write to place and cancel paper orders.
Create a key
Keys are managed with a person’s session, never with a key. Use either:
The plaintext token is returned once, at creation. Only a hash is stored; if you lose it, revoke it and create another. New keys get records:read, portfolio:read and markets:read unless you choose fewer. To trade paper, check the box in Settings, pass --trade to arena keys create, or name trade:write in the body. Live scopes are separate and off unless you tick them: trade:write:kalshi and trade:write:poly-intl. While Arena has live submission switched off, those checkboxes stay disabled. See scopes.
Limits
Rotate
Rotation creates a new key with the same label and scopes. The old key keeps working for graceSeconds (0–86,400; default 0 revokes it at once), so a deploy can switch without a gap. A rotating key does not count toward the 10-key cap.
Revoke
Revocation is immediate: the next request with that key gets 401 invalid_token. Revoking twice answers 404 key_not_found, meaning the key is already gone.
Key management endpoints
The website and CLI call these. They accept a session (browser cookie, same-origin JSON only, or a signed-in CLI’s session token as the bearer). An arena_sk_ key is refused with 401 session_required, so a leaked key cannot mint its own replacement. A guest session is refused with 403 guest_account.
Keep keys server-side. Keyed endpoints send no CORS headers: a key belongs in a server, CLI or agent runner, never in browser code. If a key is ever sent over plain HTTP, revoke it.