1. Mint the key in the torii console
Sign in to the torii console and open API Keys.API Keys: existing keys (id, scopes, last used) and the Create key form.
-
Name it so the operator can tell keys apart later —
doxaform · <your name>works. -
Tick the scopes:
- Press Create key. The secret appears once with a Copy button.
2. Bind it in Doxaform
Settings → Keys & services. Paste the secret into torii bearer token and press Save keys.After saving, the field shows a masked hint of the key instead of ○ not set.
- The status next to the field reads ○ not set until a key is bound, then a masked hint such as
sk_t…ab12. - The card’s Operator dashboard link opens the torii console — the place to connect accounts, warm sessions and mint keys.
- OpenRouter key (optional, same card): lets the wall’s AI filter turn a phrase like “tiktok from the last 6 h with 100 k+ views” into ordinary filter chips, and powers card translation. Without it those two features simply stay off.
3. Check it works
Open Monitor and look at the status strip under the wall. With a valid key, sources reportlive or cache. Two states mean the key is the problem:
Rotating or revoking
Create the new key first, save it in Doxaform, then revoke the old one in torii. Revocation is immediate: any crawl still using the old key fails with401 on its next request and the strip shows
it.
Keys are per Doxaform user. An admin’s key does not cover other users; each person binds their
own so torii’s audit trail names who ran what.