Documentation

Build with Shugoi

Precise guides and copy-ready examples, from integration to production.

Internal API keys

The internal key automates configuration; it is distinct from the siteKey and middleware secret. Create it in the dashboard and copy it once.

Endpoints

HTTP
GET /api/v1/internal/keys
POST /api/v1/internal/keys
DELETE /api/v1/internal/keys/:keyId
PATCH /api/v1/internal/sites/:siteKey/config
Authorization: Bearer <clé-api>

Payload et statuts

JSON
{"detectionFlags":{"enableWhitelist":true,"enableNativeErrorPages":false}}

200 applied; 400 invalid payload; 401 missing or revoked key; 403 operation not permitted; 404 site or key not found. Writes are audited, caches invalidated and WebSocket streams notified.

Rotation et sécurité

  1. Create a new key.
  2. Deploy it through a secret manager.
  3. Verify the call, then revoke the old key.
  4. Never expose it in a browser, Git, screenshot or client bundle.

Need help? · Support · OpenAPI