API keys
LangSmith supports two types of API keys. You can use both types of token to authenticate requests to the LangSmith API, but they have different use cases:- Personal Access Tokens (PATs) inherit the permissions of the user who created them. Use PATs for personal scripts or tools.
- Service keys scope to specific workspaces or the entire organization. Use service keys for applications and production services.
Open API Keys settings
Navigate to the Settings page and select the API Keys section.
Configure the key type
For service keys, choose between an organization-scoped and workspace-scoped key. If the key is workspace-scoped, you must specify the workspaces.Enterprise users can also assign specific workspace roles to service keys, which adjusts their permissions independently of any user.
Set expiration
Set the key’s expiration. The key becomes unusable after the number of days chosen, or never, if that is selected.
Create the key
Click Create API Key. LangSmith will display the API key only once, so make sure to copy it and store it in a safe place.
Deactivate or delete a personal access token
Deactivation temporarily stops a PAT from authenticating; deletion permanently removes it. Deactivate a token when you need to keep its record and reactivate it later. Members can deactivate, reactivate, and delete their own PATs. Organization Admins and Organization Operators can also manage every member’s PATs.
Deactivation does not change a token’s expiration date, and Reactivate key is unavailable once that date has passed. Create a new token instead.
To deactivate or delete a PAT:
- Go to Settings > API Keys and open the Personal tab.
- Find the token under My keys. To manage another member’s token, switch to All members.
- In the Actions column, select Deactivate key or Delete key. Each action opens its own confirmation dialog.
- Type the token’s description, which the dialog displays. For a token with no description, type the short key from the Key column instead.
- Select Deactivate or Delete to confirm. A success notification confirms the action.
revoke_personal_access_token and reactivation as reinstate_personal_access_token.
Service keys can only be deleted, not deactivated. Open the Service tab and select Delete key in the Actions column, then confirm with the typed description that deleting a PAT requires.
Configure the SDK
Install the SDK for your language:- Python
- TypeScript
-
LANGSMITH_ENDPOINTcontrols which LangSmith server the SDK sends data to. It defaults tohttps://api.smith.langchain.com(GCP US). Set it only if you are on a different deployment. For regional SaaS, set it to the API URL for your region:Region GCP US GCP EU GCP APAC AWS US -
LANGSMITH_WORKSPACE_IDis required only if your API key is scoped to more than one workspace. Find your Workspace ID on the Settings page under General:LANGSMITH_WORKSPACE_ID=<Workspace ID>
Use API keys outside of the SDK
See instructions for managing your organization via API.Connect these docs to your agent of choice via MCP for real-time answers.

