Skip to content

API Keys​

Long-lived fh_live_… keys for CLI and agent access. A key is sent as Authorization: Bearer fh_live_… and authenticates as the user who created it, on every endpoint that accepts a bearer session.


List my API keys​

GET
/api-keys

The authenticated user's keys, newest first. Never includes the secret. Revoked keys are excluded unless include_revoked=true.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Parameters​

Query Parameters

include_revoked
Type
string
Valid values
"true""false"
Default
"false"

Responses​

The caller's keys

application/json
JSON
{
"data": [
],
"total": 0
}

Playground​

Server
Authorization
Variables
Key
Value

Samples​


Create an API key​

POST
/api-keys

Mints a new API key for the authenticated user. The full key is returned once, in api_key, and cannot be retrieved again. key.prefix (the first 12 characters) is what later listings show.

Requires a signed-in session (the session cookies, or a Cognito JWT in the Authorization header). A request authenticated with an API key, or made while an administrator is viewing the account as its owner, answers 403.

Every new key expires: one year after creation unless expires_at asks for sooner. A key stops working early if it is revoked, if its owner's account is suspended, banned or deactivated, or if an administrator signs the owner out of every device (which revokes all of the owner's keys).

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Request Body​

application/json
JSON
{
"name": "CI deploy bot",
"expires_at": "string"
}

Responses​

Key created

application/json
JSON
{
"message": "string",
"api_key": "fh_live_3f9c2a1b0e7d4c5a8b6f1e2d3c4b5a69788766554433221100ffeeddccbbaa99",
"key": "string"
}

Playground​

Server
Authorization
Body

Samples​


Revoke an API key​

DELETE
/api-keys/{id}

Revokes one of the caller's own keys. Takes effect immediately. A key that belongs to someone else, does not exist, or is already revoked answers 404.

Requires a signed-in session: a request authenticated with an API key, or made while an administrator is viewing the account as its owner, answers 403.

Authorizations​

BearerAuth

In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.

Type
HTTP (bearer)

Parameters​

Path Parameters

id*
Type
string
Required
Format
"uuid"

Responses​

Key revoked

application/json
JSON
{
"message": "string",
"id": "string"
}

Playground​

Server
Authorization
Variables
Key
Value

Samples​


Powered by VitePress OpenAPI

Built with VitePress