Sub-Keys

Sub-keys let you split a single account across multiple integrations. Each sub-key is either a shared draw against the account balance or a hard-limit carve-out that auto-disables when spent.

Shared sub-keys

A shared sub-key authenticates against the same balance as the primary key. Spend across all shared keys is summed against the parent balance_usd.

Hard-limit sub-keys

A hard-limit sub-key carves out a fixed USD amount from the parent balance. The carve-out is reserved at mint time and refunded on revoke. The key auto-disables once spent_usd reaches the carve-out cap.

Optional caps

Show-again window

Boltch never stores the raw key string. After a sub-key is minted, the dashboard exposes the raw key for 24 hours and then drops it. Copy the key into a password manager during that window.

Hard-delete

Sub-keys with status = "revoked" can be hard-deleted from the dashboard. Hard-delete removes the row from D1 and is irreversible. Active and exhausted keys cannot be hard-deleted.