API keys
Key management is self-service: any active tenant key can mint additional keys for the same tenant. The plaintext secret is returned once at creation; later reads expose only the prefix.
Create a key#
POST
/v1/api-keysCreate a new API key for the calling tenant. Returns
201 with the plaintext secret, shown once.namerequiredstring
Key name, 1 to 100 characters.
scopesstring[]
Optional, up to 20 entries. Defaults to ["*"]; stored verbatim, enforcement reserved for a future change.
The 201 response carries { id, name, prefix, secret, scopes, created_at }. The secret is the plaintext key; subsequent reads expose only the prefix.
bash
curl -X POST https://api.lirovo.ai/v1/api-keys \
-H "Authorization: Bearer $LIROVO_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "name": "ci-prod" }'Capture the secret now
The plaintext
secret is shown only in this response. There is no way to recover it later.List keys#
GET
/v1/api-keysList this tenant's API keys. Never returns plaintext secrets, only the id, name, prefix, scopes, and timestamps. Returns
{ data, next_cursor }.bash
curl https://api.lirovo.ai/v1/api-keys \
-H "Authorization: Bearer $LIROVO_API_KEY"Revoke a key#
DELETE
/v1/api-keys/{id}Revoke an API key. Idempotent: revoking an already-revoked key returns the same
revoked_at timestamp. Returns { id, revoked_at }.You cannot revoke the key used to authenticate the current request (a footgun guard that returns 400). An unknown or cross-tenant id returns 404 API_KEY_NOT_FOUND: the same envelope for both, so existence is never leaked.
bash
curl -X DELETE https://api.lirovo.ai/v1/api-keys/key_p9q8r7 \
-H "Authorization: Bearer $LIROVO_API_KEY"