Client Api Keys

Updated Oct 4, 2026 Markdown

GET /api/v1/client/api-keys

List my API keys (reseller)

Keys owned by the calling reseller account, without secrets. Every key reaches only the client API as this account.

Responses:

Status Schema Description
200 ApiSuccess_list_ApiKeyPublic__ Successful Response

Response example (200):

JSON
{
  "data": [
    {
      "allowed_ips": "...",
      "created_at": "...",
      "id": "...",
      "key": "...",
      "last_used_at": "...",
      "name": "...",
      "owner": "...",
      "scopes": "...",
      "status": "..."
    }
  ],
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/api-keys

POST /api/v1/client/api-keys

Create an API key bound to my account (reseller)

Mint an HMAC key pair bound to the calling reseller account. The secret is returned only once. The key's scope is fixed to the client API; the reseller's ACL plan must grant api_access.

Body fields:

Field Type Required Notes
allowed_ips array no —
name string yes minLength=1; maxLength=100
scopes array no —

Request body example:

JSON
{
  "allowed_ips": [
    "string"
  ],
  "name": "string",
  "scopes": [
    "string"
  ]
}

Responses:

Status Schema Description
201 ApiSuccess_ApiKeyCreateResponse_ Successful Response
422 HTTPValidationError Validation Error

Response example (201):

JSON
{
  "data": {
    "allowed_ips": [
      "..."
    ],
    "created_at": "string",
    "id": "string",
    "key": "string",
    "name": "string",
    "owner": "...",
    "scopes": [
      "..."
    ],
    "secret": "string"
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/api-keys

GET /api/v1/client/api-keys/logs

Access logs of my API keys (reseller)

Paginated history of the requests signed with keys owned by the calling reseller.

Query parameters:

Name Type Required Notes
page integer no minimum=1
limit integer no minimum=1; maximum=100
search string no —
status string no —

Responses:

Status Schema Description
200 ApiSuccess_PaginatedApiAccessLogsData_ Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "data": {
    "logs": [
      "..."
    ],
    "total": 0
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/api-keys/logs

DELETE /api/v1/client/api-keys/{key_id}

Delete one of my API keys (reseller)

Permanently remove a key owned by the calling reseller. The audit log entry is kept.

Path parameters:

Name Type Required Notes
key_id string yes —

Responses:

Status Schema Description
200 MessageResponse Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "message": "string",
  "status": "success"
}

cURL example:

shell
curl -X DELETE \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/api-keys/{key_id}

PUT /api/v1/client/api-keys/{key_id}

Update one of my API keys (reseller)

Change the name or the allowed-IP list of a key owned by the calling reseller. The scope cannot change.

Path parameters:

Name Type Required Notes
key_id string yes —

Body fields:

Field Type Required Notes
allowed_ips array no —
name string no —
scopes array no —

Request body example:

JSON
{
  "allowed_ips": [
    "string"
  ],
  "name": "string",
  "scopes": [
    "string"
  ]
}

Responses:

Status Schema Description
200 ApiSuccess_ApiKeyPublic_ Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "data": {
    "allowed_ips": [
      "..."
    ],
    "created_at": "string",
    "id": "string",
    "key": "string",
    "last_used_at": "...",
    "name": "string",
    "owner": "...",
    "scopes": [
      "..."
    ],
    "status": "active"
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X PUT \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/api-keys/{key_id}

POST /api/v1/client/api-keys/{key_id}/revoke

Revoke one of my API keys (reseller)

Soft-disable a key owned by the calling reseller; later requests signed with it are rejected with 401.

Path parameters:

Name Type Required Notes
key_id string yes —

Responses:

Status Schema Description
200 ApiSuccess_ApiKeyPublic_ Successful Response
422 HTTPValidationError Validation Error

Response example (200):

JSON
{
  "data": {
    "allowed_ips": [
      "..."
    ],
    "created_at": "string",
    "id": "string",
    "key": "string",
    "last_used_at": "...",
    "name": "string",
    "owner": "...",
    "scopes": [
      "..."
    ],
    "status": "active"
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}

cURL example:

shell
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/api-keys/{key_id}/revoke
Still Need Help?

Our support team is here around the clock for anything you can't find above.