# Client Api Keys

<a id="get-api-v1-client-api-keys"></a>
#### `GET /api/v1/client/api-keys`

*List my API keys (reseller)*

Keys owned by the calling reseller account, without secrets. Every key reaches only the client API as this account.

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_list_ApiKeyPublic__` | Successful Response |

**Response example (200):**

```json
{
  "data": [
    {
      "allowed_ips": "...",
      "created_at": "...",
      "id": "...",
      "key": "...",
      "last_used_at": "...",
      "name": "...",
      "owner": "...",
      "scopes": "...",
      "status": "..."
    }
  ],
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/api-keys
```

---

<a id="post-api-v1-client-api-keys"></a>
#### `POST /api/v1/client/api-keys`

*Create an API key bound to my account (reseller)*

Mint an HMAC key pair bound to the calling reseller account. **The secret is returned only once.** The key's scope is fixed to the client API; the reseller's ACL plan must grant `api_access`.

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `allowed_ips` | array<string> | no | — |
| `name` | string | yes | minLength=1; maxLength=100 |
| `scopes` | array<string> | no | — |

**Request body example:**

```json
{
  "allowed_ips": [
    "string"
  ],
  "name": "string",
  "scopes": [
    "string"
  ]
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `201` | `ApiSuccess_ApiKeyCreateResponse_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (201):**

```json
{
  "data": {
    "allowed_ips": [
      "..."
    ],
    "created_at": "string",
    "id": "string",
    "key": "string",
    "name": "string",
    "owner": "...",
    "scopes": [
      "..."
    ],
    "secret": "string"
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/api-keys
```

---

<a id="get-api-v1-client-api-keys-logs"></a>
#### `GET /api/v1/client/api-keys/logs`

*Access logs of my API keys (reseller)*

Paginated history of the requests signed with keys owned by the calling reseller.

**Query parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `page` | integer | no | minimum=1 |
| `limit` | integer | no | minimum=1; maximum=100 |
| `search` | string | no | — |
| `status` | string | no | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_PaginatedApiAccessLogsData_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "logs": [
      "..."
    ],
    "total": 0
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X GET \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/api-keys/logs
```

---

<a id="delete-api-v1-client-api-keys-key-id"></a>
#### `DELETE /api/v1/client/api-keys/{key_id}`

*Delete one of my API keys (reseller)*

Permanently remove a key owned by the calling reseller. The audit log entry is kept.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `key_id` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `MessageResponse` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "message": "string",
  "status": "success"
}
```

**cURL example:**

```bash
curl -X DELETE \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/api-keys/{key_id}
```

---

<a id="put-api-v1-client-api-keys-key-id"></a>
#### `PUT /api/v1/client/api-keys/{key_id}`

*Update one of my API keys (reseller)*

Change the name or the allowed-IP list of a key owned by the calling reseller. The scope cannot change.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `key_id` | string | yes | — |

**Body fields:**

| Field | Type | Required | Notes |
|-------|------|----------|-------|
| `allowed_ips` | array<string> | no | — |
| `name` | string | no | — |
| `scopes` | array<string> | no | — |

**Request body example:**

```json
{
  "allowed_ips": [
    "string"
  ],
  "name": "string",
  "scopes": [
    "string"
  ]
}
```

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_ApiKeyPublic_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "allowed_ips": [
      "..."
    ],
    "created_at": "string",
    "id": "string",
    "key": "string",
    "last_used_at": "...",
    "name": "string",
    "owner": "...",
    "scopes": [
      "..."
    ],
    "status": "active"
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X PUT \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  -H "Content-Type: application/json" \
  -d @body.json \
  https://your-server:2000/api/v1/client/api-keys/{key_id}
```

---

<a id="post-api-v1-client-api-keys-key-id-revoke"></a>
#### `POST /api/v1/client/api-keys/{key_id}/revoke`

*Revoke one of my API keys (reseller)*

Soft-disable a key owned by the calling reseller; later requests signed with it are rejected with 401.

**Path parameters:**

| Name | Type | Required | Notes |
|------|------|----------|-------|
| `key_id` | string | yes | — |

**Responses:**

| Status | Schema | Description |
|--------|--------|-------------|
| `200` | `ApiSuccess_ApiKeyPublic_` | Successful Response |
| `422` | `HTTPValidationError` | Validation Error |

**Response example (200):**

```json
{
  "data": {
    "allowed_ips": [
      "..."
    ],
    "created_at": "string",
    "id": "string",
    "key": "string",
    "last_used_at": "...",
    "name": "string",
    "owner": "...",
    "scopes": [
      "..."
    ],
    "status": "active"
  },
  "message": "",
  "status": "success",
  "warnings": [
    "string"
  ]
}
```

**cURL example:**

```bash
curl -X POST \
  -H "X-WHost-Key: $WHOST_API_KEY" \
  -H "X-WHost-Timestamp: $(date +%s)" \
  -H "X-WHost-Nonce: $(openssl rand -hex 16)" \
  -H "X-WHost-Signature: $(compute_hmac)" \
  https://your-server:2000/api/v1/client/api-keys/{key_id}/revoke
```

---
