Skip to content

Create an API key​

POST
/api-keys

Mints a new API key for the authenticated user. The full key is returned once, in api_key, and cannot be retrieved again. key.prefix (the first 12 characters) is what later listings show.

Requires a signed-in session (the session cookies, or a Cognito JWT in the Authorization header). A request authenticated with an API key, or made while an administrator is viewing the account as its owner, answers 403.

Every new key expires: one year after creation unless expires_at asks for sooner. A key stops working early if it is revoked, if its owner's account is suspended, banned or deactivated, or if an administrator signs the owner out of every device (which revokes all of the owner's keys).

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
"name": "CI deploy bot",
"expires_at": "string"
}

Responses​

Key created

application/json
JSON
{
"message": "string",
"api_key": "fh_live_3f9c2a1b0e7d4c5a8b6f1e2d3c4b5a69788766554433221100ffeeddccbbaa99",
"key": "string"
}

Playground​

Server
Authorization
Body

Samples​

Powered by VitePress OpenAPI

Built with VitePress