Skip to main content
API keys are the primary authentication mechanism for PitPath Chrono. Every key belongs to a license and carries an access role that controls which endpoints it can call. When you create a key, the full token is returned exactly once — store it immediately. All subsequent reads return only the key’s metadata and a short keyPrefix for identification.
The full token value is only present in the POST /api/v1/api-keys response. It cannot be retrieved later. If you lose it, revoke the key and create a new one.

GET /api/v1/api-keys

Return all API keys that belong to your current license. Required role: Any authenticated user with key-view permission
The response is an array of API key metadata objects. The full token is not included.
string (UUID)
required
Unique identifier for the API key.
string (UUID)
required
UUID of the license this key belongs to.
string
required
Descriptive label for the key.
string
required
First few characters of the token, useful for identifying the key without exposing its full value.
string
required
Access role granted to this key. One of R, CR, CRUD, or ADMIN.
boolean
required
Whether this key is currently active.
string (ISO 8601)
Timestamp of the most recent request authenticated with this key. null if never used.
string (ISO 8601)
required
Timestamp when the key was created.
string (ISO 8601)
required
Timestamp of the most recent update to the key.

POST /api/v1/api-keys

Create a new API key for your current license. Returns the full token in a one-time response. Required role: Key-management permission
string
required
A descriptive label for the key. Must be 3–120 characters and must not be blank.
string
required
The access role to assign. One of R, CR, CRUD, or ADMIN.
object
required
Metadata for the newly created key.
string
required
The full API key token. This value is returned only once — store it in a secure location immediately.

PATCH /api/v1/api-keys/

Update the name or role of an existing API key. All fields are optional — only the fields you include are changed. Required role: Key-management permission
string (UUID)
required
UUID of the API key to update.
string
New label for the key. Must be 3–120 characters and must not be blank or whitespace-only.
string
New access role to assign. One of R, CR, CRUD, or ADMIN.
The response is the updated API key object with the same shape as a single item from GET /api/v1/api-keys. The full token is not included.

DELETE /api/v1/api-keys/

Permanently revoke an API key. Any in-flight requests using the key will fail immediately. This action cannot be undone. Required role: Key-management permission
string (UUID)
required
UUID of the API key to revoke.
Returns 204 No Content on success with an empty body.