---
title: "Key"
description: "a second kind of caller: a key with an identity of its own"
section: concepts
address: /concepts/key
contract: 0476e35e6e275db5
---

# Key

a second kind of caller: a key with an identity of its own

[figure: Key is a definition at tenant scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | definition |
| scope | tenant |
| key | its id |
| store | postgres |
| family | people |



## Fields


| field | type | required | note |
|---|---|---|---|
| `owner` | `one of the platform \| a tenant` | yes |  |
| `acts_for` | `id` | yes | the one person or service it may act for |
| `scopes` | [Scope](/concepts/scope) | yes |  |
| `access_scopes` | [AccessScope](/concepts/accessscope) | yes |  |
| `mode` | `one of read only \| propose \| act \| full autonomy` | yes |  |
| `ends_at` | `time` | no |  |
| `withdrawn_at` | `time` | no |  |



## Routes that use it
No route takes or returns Key directly. The record holds it, and the objects that point at it reach it.
