API keys
Planned management contract. Supported clients use personal capture tokens.
Planned capability
This page describes a proposed management contract, not a setup procedure. Current request behavior is documented in the Gateway API reference.
Current serving identity
Current clients use a personal cct_ capture token from Credentials. This includes clients that run without Cortex Defender. A provider API key stays on Gateway.
Administrator-created cgw_ virtual keys currently record ownership and policy metadata. Per-key serving budgets, expiry, rotation and revocation enforcement are proposed behavior; do not use these records as the supported serving credential.
Proposed ownership and funding
A future key contract would assign an explicit person or service owner and a funding scope. It would need to define attribution, concurrent accounting and how per-key limits would combine with the owner's applicable policies. Proposed Used, Reserved and Remaining fields would require admission accounting rather than subtraction from captured reporting spend.
Proposed lifecycle
Expiry, rotation, grace periods, immediate blocking and retained history would need a serving contract and verification on the affected client path. The supported personal-token setup above does not establish these virtual-key guarantees.