Sub-Keys
Sub-keys let you split a single account across multiple integrations. Each sub-key is either a shared draw against the account balance or a hard-limit carve-out that auto-disables when spent.
Shared sub-keys
A shared sub-key authenticates against the same balance as the primary key. Spend across all shared keys is summed against the parent balance_usd.
Hard-limit sub-keys
A hard-limit sub-key carves out a fixed USD amount from the parent balance. The carve-out is reserved at mint time and refunded on revoke. The key auto-disables once spent_usd reaches the carve-out cap.
Optional caps
budget_cap_usd: stops the key when projected spend would exceed the cap.token_cap: stops the key when projected input plus output tokens would exceed the cap.
Show-again window
Boltch never stores the raw key string. After a sub-key is minted, the dashboard exposes the raw key for 24 hours and then drops it. Copy the key into a password manager during that window.
Hard-delete
Sub-keys with status = "revoked" can be hard-deleted from the dashboard. Hard-delete removes the row from D1 and is irreversible. Active and exhausted keys cannot be hard-deleted.