API Keys

Create, list, update, and deactivate API keys.

All endpoints on this page require a session token from POST /auth/login.

List keys

GET /account/keys

Returns all API keys for your account.

Response 200

{
  "keys": [
    {
      "id": "key-uuid",
      "key_prefix": "a1b2c3d4",
      "allowed_origins": ["https://example.com"],
      "label": "Production server",
      "active": true,
      "created_at": "2026-04-01T12:00:00Z",
      "last_used_at": "2026-04-05T08:30:00Z"
    }
  ]
}

Create a key

POST /account/keys

Create a new API key. The request body is optional — an empty body creates an unrestricted server-side key.

Request body (all fields optional):

{
  "allowed_origins": ["https://example.com", "https://app.example.com"],
  "label": "Production server"
}
FieldTypeDescription
allowed_originsstring[]Up to 10 exact origins for client-side use. Omit for server-side keys.
labelstringHuman-readable name (max 100 characters)

Response 201

{
  "key": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6",
  "id": "key-uuid",
  "key_prefix": "a1b2c3d4",
  "allowed_origins": ["https://example.com"],
  "label": "Production server",
  "active": true,
  "created_at": "2026-04-01T12:00:00Z"
}

::: warning The key value is shown only once. Store it securely — it cannot be retrieved again. :::

Update a key

POST /account/keys/{id}

Update a key's origin restrictions or label.

Request body (all fields optional):

{
  "allowed_origins": ["https://new-domain.com"],
  "label": "Updated label"
}

Set allowed_origins to null to remove origin restrictions (converts to a server-side key).

Response 200 — returns the updated key metadata.

Deactivate a key

DELETE /account/keys/{id}

Soft-deletes a key by setting it to inactive. The key can no longer be used for API requests.

Response 200

{
  "deleted": true
}