API Keys Management
Creating, revoking, and rotating API keys is done exclusively from the MonCréneau web dashboard, by a STAFF user (ADMIN or OWNER role) authenticated via a session.
A third-party external application cannot call these endpoints. They are authenticated by session cookie (web login), not by API key (X-API-Key) — an API key cannot be used to manage other API keys. This page describes the behavior for reference, not as an integration you can build from your own code.
Required access
- Authenticated session via the web interface (session cookie)
- ADMIN or OWNER role
List API keys
GET /api/staff/api-keys
200 response:
[
{
"id": 42,
"name": "Production API Key",
"maskedKey": "mk_live_...***",
"environment": "LIVE",
"scopes": ["READ_APPOINTMENTS", "WRITE_APPOINTMENTS"],
"rateLimitPerHour": 1000,
"isActive": true,
"createdAt": "2026-01-15T10:00:00",
"lastUsedAt": "2026-01-22T08:30:00"
}
]
Create an API key
POST /api/staff/api-keys — { "name": "...", "environment": "LIVE", "scopes": ["READ_APPOINTMENTS"], "rateLimitPerHour"?: 1000 }.
The plaintext key (mk_live_.../mk_test_...) is only visible once, in the creation response — save it immediately, it will never be shown again (only maskedKey remains visible afterward).
Revoke an API key
DELETE /api/staff/api-keys/{id} — deactivates the key (isActive=false), irreversible.
Rotate an API key
POST /api/staff/api-keys/{id}/rotate — revokes the existing key and generates a new one in the same operation (atomic transaction: there is never a window where both are valid or neither is). As with creation, the new plaintext key is only visible once in the response.
Available scopes
See Scopes for the complete list of permissions.