Skip to main content
API keys are the primary way to authenticate requests to PitPath Chrono. Each key is scoped to a single license and carries an access role that controls what the key can do. The server stores only a hashed copy of the key value — you identify a key by its human-readable name and its short keyPrefix, which is the visible prefix displayed in listings.
The full API key value is returned only once, in the response to the creation request. Copy it to a secure secrets store immediately. It cannot be retrieved again.
You can only manage API keys that belong to your own license. Operations on keys from another license will return a 403 error.

Create a key

Send a POST request to /api/v1/api-keys with a name (3–120 characters) and a role. The response body contains both the key metadata (apiKey) and the plain-text token you will use in subsequent requests.
Response — 201 Created
The token field is the complete key you pass in the X-API-Key header. The keyPrefix is the short prefix shown in all future listings — it lets you identify which key you are looking at without exposing the full value.

List keys

Send a GET request to /api/v1/api-keys to retrieve all keys for your license. The response is an array of API key objects. The full key value is never included in list responses — only the keyPrefix and metadata are returned.
Response — 200 OK

Update a key

Send a PATCH request to /api/v1/api-keys/{apiKeyId} to change the key’s name, role, or enabled status. All fields are optional — include only what you want to change.
The response is the updated API key object. Disabling a key ("enabled": false) causes it to be rejected immediately on the next request.

Revoke a key

Send a DELETE request to /api/v1/api-keys/{apiKeyId} to permanently remove a key. Revocation takes effect immediately.
A successful revocation returns 204 No Content with an empty body.