Skip to main content

API Keys Management

Web dashboard only — not accessible via API key

Creating, revoking, and rotating API keys is done exclusively from the MonCréneau web dashboard, by a STAFF user (ADMIN or OWNER role) authenticated via a session.

A third-party external application cannot call these endpoints. They are authenticated by session cookie (web login), not by API key (X-API-Key) — an API key cannot be used to manage other API keys. This page describes the behavior for reference, not as an integration you can build from your own code.

Required access​

  • Authenticated session via the web interface (session cookie)
  • ADMIN or OWNER role

List API keys​

GET /api/staff/api-keys

200 response:

[
{
"id": 42,
"name": "Production API Key",
"maskedKey": "mk_live_...***",
"environment": "LIVE",
"scopes": ["READ_APPOINTMENTS", "WRITE_APPOINTMENTS"],
"rateLimitPerHour": 1000,
"isActive": true,
"createdAt": "2026-01-15T10:00:00",
"lastUsedAt": "2026-01-22T08:30:00"
}
]

Create an API key​

POST /api/staff/api-keys — { "name": "...", "environment": "LIVE", "scopes": ["READ_APPOINTMENTS"], "rateLimitPerHour"?: 1000 }.

The plaintext key (mk_live_.../mk_test_...) is only visible once, in the creation response — save it immediately, it will never be shown again (only maskedKey remains visible afterward).

Revoke an API key​

DELETE /api/staff/api-keys/{id} — deactivates the key (isActive=false), irreversible.

Rotate an API key​

POST /api/staff/api-keys/{id}/rotate — revokes the existing key and generates a new one in the same operation (atomic transaction: there is never a window where both are valid or neither is). As with creation, the new plaintext key is only visible once in the response.

Available scopes​

See Scopes for the complete list of permissions.