API reference

API keys

Key management is self-service: any active tenant key can mint additional keys for the same tenant. The plaintext secret is returned once at creation; later reads expose only the prefix.

Create a key#

POST/v1/api-keys
Create a new API key for the calling tenant. Returns 201 with the plaintext secret, shown once.
namerequired
string

Key name, 1 to 100 characters.

scopes
string[]

Optional, up to 20 entries. Defaults to ["*"]; stored verbatim, enforcement reserved for a future change.

The 201 response carries { id, name, prefix, secret, scopes, created_at }. The secret is the plaintext key; subsequent reads expose only the prefix.

bash
curl -X POST https://api.lirovo.ai/v1/api-keys \
  -H "Authorization: Bearer $LIROVO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "name": "ci-prod" }'
Capture the secret now
The plaintext secret is shown only in this response. There is no way to recover it later.

List keys#

GET/v1/api-keys
List this tenant's API keys. Never returns plaintext secrets, only the id, name, prefix, scopes, and timestamps. Returns { data, next_cursor }.
bash
curl https://api.lirovo.ai/v1/api-keys \
  -H "Authorization: Bearer $LIROVO_API_KEY"

Revoke a key#

DELETE/v1/api-keys/{id}
Revoke an API key. Idempotent: revoking an already-revoked key returns the same revoked_at timestamp. Returns { id, revoked_at }.

You cannot revoke the key used to authenticate the current request (a footgun guard that returns 400). An unknown or cross-tenant id returns 404 API_KEY_NOT_FOUND: the same envelope for both, so existence is never leaked.

bash
curl -X DELETE https://api.lirovo.ai/v1/api-keys/key_p9q8r7 \
  -H "Authorization: Bearer $LIROVO_API_KEY"