API Keys
Create, list, update, and deactivate API keys.
All endpoints on this page require a session token from POST /auth/login.
List keys
GET /account/keys
Returns all API keys for your account.
Response 200
Create a key
POST /account/keys
Create a new API key. The request body is optional — an empty body creates an unrestricted server-side key.
Request body (all fields optional):
Response 201
::: warning
The key value is shown only once. Store it securely — it cannot be retrieved again.
:::
Update a key
POST /account/keys/{id}
Update a key's origin restrictions or label.
Request body (all fields optional):
Set allowed_origins to null to remove origin restrictions (converts to a server-side key).
Response 200 — returns the updated key metadata.
Deactivate a key
DELETE /account/keys/{id}
Soft-deletes a key by setting it to inactive. The key can no longer be used for API requests.
Response 200