API Keys
Long-lived fh_live_… keys for CLI and agent access. A key is sent as Authorization: Bearer fh_live_… and authenticates as the user who created it, on every endpoint that accepts a bearer session.
List my API keys
The authenticated user's keys, newest first. Never includes the secret. Revoked keys are excluded unless include_revoked=true.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Parameters
Query Parameters
"true""false""false"Responses
The caller's keys
Create an API key
Mints a new API key for the authenticated user. The full key is returned once, in api_key, and cannot be retrieved again. key.prefix (the first 12 characters) is what later listings show.
Requires a signed-in session (the session cookies, or a Cognito JWT in the Authorization header). A request authenticated with an API key, or made while an administrator is viewing the account as its owner, answers 403.
Every new key expires: one year after creation unless expires_at asks for sooner. A key stops working early if it is revoked, if its owner's account is suspended, banned or deactivated, or if an administrator signs the owner out of every device (which revokes all of the owner's keys).
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Request Body
Responses
Key created
Revoke an API key
Revokes one of the caller's own keys. Takes effect immediately. A key that belongs to someone else, does not exist, or is already revoked answers 404.
Requires a signed-in session: a request authenticated with an API key, or made while an administrator is viewing the account as its owner, answers 403.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Parameters
Path Parameters
"uuid"Responses
Key revoked