Migrating from personal access tokens
Personal access tokens are a dashboard credential. API keys are the public /v1 credential. They do not share middleware, error-code casing, or account switching.
What changes
- Host and path stay on api.{domain}/v1 — still no /api prefix.
- Header is still Authorization: Bearer, but the secret starts with agy_.
- Scopes use resource:verb (chatbots:read), not the PAT catalog.
- X-Account-Id is rejected. A key is pinned to the account that minted it.
- Error codes are SCREAMING_SNAKE.
What to do
- Mint an API key with the scopes your PAT used.
- Point the client at the same host, new secret.
- Switch error handling to error.code in SCREAMING_SNAKE.
- Revoke the PAT when the cutover is done.