X-API-Key HTTP header and are scoped to a role that controls what operations the caller can perform.
How API key authentication works
When you make a request, Chrono reads theX-API-Key header, looks up the matching key, and checks whether the associated role permits the requested operation. There are no session cookies, no OAuth flows, and no bearer tokens — just the key in the header.
Always store API keys in a secrets manager or environment variable. Never hard-code them in source code or check them into version control.
Getting an API key
Your first ADMIN key is provisioned when your license is created by the PitPath team. To create additional keys, use the API keys endpoint with a key that has at leastCR role.
- curl
- fetch
Example response
name field must be between 3 and 120 characters. Use a descriptive name so you can identify the key’s purpose when listing all keys later.
Roles
Every API key has exactly one role. Roles are cumulative — a higher role includes all permissions of lower roles.Choosing the right role
- Use
Rfor dashboards, public leaderboards, or any integration that only needs to display data. - Use
CRfor sim rigs. When Chrono registers a rig, it auto-generates aCRkey for that rig to submit laps. - Use
CRUDfor your primary results management software that needs to correct or delete records. - Use
ADMINonly for your back-office tools that manage the license itself or provision other ADMIN keys.
Using a key in a request
Include the key in every request via theX-API-Key header. There is no separate login step.
- curl
- fetch
Listing your API keys
To see all keys associated with your license, use a key with at leastCR role:
- curl
- fetch
keyPrefix is returned (e.g. chrono_cr_) but the full token is never exposed after initial creation.
Rotating a key
To rotate a key, create a new one with the desired role, deploy it to your application, then revoke the old key. There is no in-place secret rotation — the token value is fixed at creation. Step 1 — Create the replacement key:curl
curl
204 No Content.
Revocation is immediate and permanent. Make sure the new key is deployed and working before you delete the old one.