API Keys
The caller's own API keys, under /me: a key belongs to a user and acts as them on every tenant they are a member of. The key itself is shown once, when it is issued; the list carries its name, dates and whether it is still active. Issuing and deleting need a bearer token (403 with an API key), so a key cannot issue or delete keys.
-
GET List My API KeysThe caller's API keys, newest first, expired ones included. The keys themselves are not returned: a key is shown once, when it is issued./me/api-keys
-
POST Create My API KeyIssues the caller an API key, which acts as them on every tenant they are a member of. The key is returned this once and cannot be read back. Bearer t.../me/api-keys
-
DELETE Delete My API KeyDeletes the key: it stops authenticating at once. Bearer token only: 403 with an API key. 404 when the caller has no key with the code./me/api-keys/{key}