Internal API keys
The internal key automates configuration; it is distinct from the siteKey and middleware secret. Create it in the dashboard and copy it once.
Endpoints
HTTP
GET /api/v1/internal/keysPOST /api/v1/internal/keysDELETE /api/v1/internal/keys/:keyIdPATCH /api/v1/internal/sites/:siteKey/configAuthorization: Bearer <clé-api>Payload et statuts
JSON
{"detectionFlags":{"enableWhitelist":true,"enableNativeErrorPages":false}}200 applied; 400 invalid payload; 401 missing or revoked key; 403 operation not permitted; 404 site or key not found. Writes are audited, caches invalidated and WebSocket streams notified.
Rotation et sécurité
- Create a new key.
- Deploy it through a secret manager.
- Verify the call, then revoke the old key.
- Never expose it in a browser, Git, screenshot or client bundle.