CloudZero uses key-based authorization to secure API access. To authenticate your requests, include your API key in the Authorization header:
curl -X GET https://api.cloudzero.com/v2/insights \
-H "Authorization: AbCd1234EfGh5678AbCd1234EfGh5678AbCd12"This is not a bearer token, so there is no
Bearerprefix in the Authorization header.
Manage API keys
An organization can have multiple API keys. To view and manage all API keys for your organization, navigate to Settings > API Keys.
Only users with the necessary permissions can manage keys. Each key can be assigned one or more API scopes, which grant access to specific endpoints in the CloudZero API.
The API Keys page displays a list of keys with the following information:
- Name
- Description
- Created By: Email of the user who created the key
- Updated By: Email of the user who last modified the key
- Last Modified: Last update timestamp
- Last Accessed: Last usage timestamp, or "Not In Use" if the key has never been used
- Scopes: Number of granted API scopes
- Status:
EnabledorDisabled
If your organization had an API key before multiple keys were supported, it is listed as Legacy API Key.
CloudZero does not automatically grant access to new API endpoints. When new endpoints are released, you must edit each API key to manually add the necessary scopes.
Create an API key
-
Navigate to Settings > API Keys.
-
Select Create API Key.
-
Enter a name for the key (minimum 3 characters, must be unique).
-
Enter a description (optional).
-
Under Scopes, select the API scopes to assign to the key. You must select at least one. Use the search bar or expand categories to find specific scopes. For information about each scope, refer to API key scopes.
- Select Create API Key.
- Copy the API key displayed. It will not be shown again.
- Select Done.
New keys are Enabled by default.
Edit an API key
- On the API Keys page, locate the key you want to modify.
- Click the key name, or select the three-dot icon in the Actions column and select Edit.
- Modify the Name, Description, or Scopes as needed. For information about each scope, refer to API key scopes.
- Select Save Changes.
Enable or disable an API key
- On the API Keys page, locate the key you want to modify.
- Select the three-dot icon in the Actions column.
- Select Enable or Disable.
The Status column updates to reflect the change.
Delete an API key
Deleting an API key immediately revokes access for any services using it. This action cannot be undone.
- On the API Keys page, locate the key you want to delete.
- Select the three-dot icon in the Actions column.
- Select Delete.
- Type the exact name of the API key to confirm deletion.
- Select Delete.
API key scopes
CloudZero organizes API scopes into categories. Each scope grants access to specific API endpoints. When creating or editing an API key, select the scopes that match how the key will be used.
Cost & Usage Data
Read cost, usage, dimension, and resource-tag data via the API.
billing:read_costs: Get billing costsbilling:read_dimensions: Get billing dimensionsbilling:read_resource_tags: Read resource tag data
Views
Create, read, update, and delete saved Views.
views:create_view: Create a Viewviews:delete_view: Delete a Viewviews:read_view: Get one Viewviews:read_views: Get a list of Viewsviews:update_view: Update a View
Budgets
Create, read, update, and delete budgets.
budgets:create_budget: Create a budgetbudgets:delete_budget: Delete a budgetbudgets:read_budget: Get one budgetbudgets:read_budgets: Get a list of budgetsbudgets:update_budget: Update a budget
Insights & Anomalies
Create, read, update, and comment on cost anomalies and insights.
insights:create_insight: Create an insightinsights:create_insight_comment: Create a comment for an insightinsights:delete_insight: Delete an insightinsights:read_insight: Get one insightinsights:read_insight_comments: Get a list of comments for an insightinsights:read_insights: Get a list of insightsinsights:update_insight: Update an insightinsights:update_insight_comment: Update a comment for an insight
Optimization & Savings
Read and manage savings recommendations and their comments.
optimize:check: Check optimization statusoptimize:create_comments: Create recommendation commentsoptimize:delete_comment: Delete a recommendation commentoptimize:get_available_dimensions: Get available dimensions for optimizationoptimize:get_recommendation: Get one recommendationoptimize:get_recommendation_type: Get one recommendation typeoptimize:list_comments: List recommendation commentsoptimize:list_recommendation_types: List recommendation typesoptimize:list_recommendations: List recommendationsoptimize:update_comment: Update a recommendation commentoptimize:update_recommendation_type: Update a recommendation typeoptimize:update_recommendations: Update recommendations
Cost Allocation (CostFormation)
Manage CostFormation definitions, namespaces, and publish jobs for cost allocation.
costformation:cancel_publish_job: Cancel a publish jobcostformation:create_definition_async: Create a definition asynchronouslycostformation:create_definition_version: Create a CostFormation definition versioncostformation:create_namespace: Create a namespacecostformation:create_namespaced_definition_async: Create a namespaced definition asynchronouslycostformation:delete_namespace: Delete a namespacecostformation:list_publish_jobs: List publish jobscostformation:read_all_namespaces: Read all namespacescostformation:read_definition_version: Get one CostFormation definition versioncostformation:read_definition_versions: Get a list of CostFormation definition versionscostformation:read_namespace: Read one namespacecostformation:read_publish_job: Read one publish jobcostformation:update_namespace: Update a namespace
Kubernetes
Send Kubernetes container metrics and manage cluster details.
container-metrics_v1:abandon: Required scope for the CloudZero Agent for Kubernetescontainer-metrics_v1:get-status: Required scope for the CloudZero Agent for Kubernetescontainer-metrics_v1:legacy: Required scope for the CloudZero Agent for Kubernetescontainer-metrics_v1:upload: Required scope for the CloudZero Agent for Kubernetescontainer:get-clusters: Get Kubernetes cluster detailscontainer:update-cluster: Update Kubernetes cluster details
Cloud & Billing Connections
Create and manage cloud billing connections, including AnyCost Stream connections.
connections:create_billing: Create a billing connectionconnections:create_billing_anycost_billing_drop: Create an AnyCost Stream connection billing dropconnections:create_billing_anycost_validate_billing_drop: Validate an AnyCost Stream connection billing dropconnections:delete_billing: Delete a billing connectionconnections:read_billing: Get one billing connectionconnections:read_billing_anycost_billing_drops: Get a list of billing drops for an AnyCost Stream connectionconnections:read_billing_anycost_billing_drops_month: Get contents of one billing drop for an AnyCost Stream connectionconnections:read_billings: Get a list of billing connectionsconnections:update_billing: Update a billing connection
AI Telemetry
Ingest AI inference telemetry from supported platforms and collectors.
ai-telemetry-ingest:ingest-ai-inference-event-v2: Ingest AI inference events (v2)ai-telemetry-ingest:ingest-bifrost-v1: Ingest telemetry from Bifrostai-telemetry-ingest:ingest-claude-code-v1: Ingest telemetry from Claude Codeai-telemetry-ingest:ingest-cz-collector-v1: Ingest telemetry from the CloudZero macOS Collectorai-telemetry-ingest:ingest-cz-telemetry-v1: Ingest CloudZero telemetry (v1)ai-telemetry-ingest:ingest-litellm-v1: Ingest telemetry from LiteLLMai-telemetry-ingest:ingest-otel-genai-v1: Ingest telemetry via OpenTelemetryai-telemetry-ingest:ingest-otlp-v1: Ingest telemetry via OTLP (v1)
AI Hub (MCP)
Access the CloudZero AI Hub over MCP for AI assistants and agents.
ai-hub:mcp: Connect to the AI Hub MCP endpoint
Telemetry & Usage Streams
Create and manage unit-cost telemetry streams and submit telemetry records.
events_v1:create_event: Post an eventunit-cost_v1:create_telemetry_stream: Create a telemetry streamunit-cost_v1:delete_telemetry_stream: Delete a telemetry streamunit-cost_v1:manage_telemetry_records: Manage telemetry records for allocation and unit cost metric streams. Grants access to post, sum, replace, and delete records for both allocation telemetry and unit cost metric telemetry streams.unit-cost_v1:read_telemetry: Get telemetry stream records and Get metrics records
Roles & Access Control
Manage CloudZero roles and read permission sets via the API.
access-control:create_role: Create a roleaccess-control:delete_role: Delete a roleaccess-control:read_permission_sets: Read permission setsaccess-control:read_role: Read one roleaccess-control:read_roles: Read all rolesaccess-control:update_role: Update a role
If you need help, contact your account manager.

