Skip to content

Manage API keys

Create, rotate, list, and revoke tenant API keys safely.

CryptoSwift tenant API keys authenticate Client API requests through the X-Api-Key header. Manage keys from a trusted backend or an authenticated administrator session. Never expose them in browser or mobile application code.

The API key management endpoints are available at /tenant/me/api-keys in both Sandbox and Production. The two environments use separate credentials.

List API keys

curl --location 'https://api-dev.cryptoswift.eu/tenant/me/api-keys' \
  --header "X-Api-Key: $API_KEY"

Each record includes id, apiKey, expiresAt, createdAt, and revokedAt. A key is no longer valid after it expires or is revoked. Treat list responses as sensitive because they contain usable key material.

Create a key

Create a key without an expiry:

curl --request POST 'https://api-dev.cryptoswift.eu/tenant/me/api-keys' \
  --header "X-Api-Key: $API_KEY" \
  --header 'Content-Type: application/json' \
  --data '{}'

To create a short-lived key, supply a future ISO 8601 timestamp:

{
  "expiresAt": "2030-01-31T23:59:59.000Z"
}

Store the returned apiKey in a secrets manager immediately. Do not commit it, log it, or send it to a frontend.

Rotate a key

Use overlapping rotation so integrations do not lose access:

  1. Create a new key.
  2. Store it in your secret manager and deploy it to every service that calls CryptoSwift.
  3. Verify requests with the new key in the relevant environment.
  4. Revoke the old key.

Revoke a key

curl --request DELETE 'https://api-dev.cryptoswift.eu/tenant/me/api-keys/{apiKeyId}' \
  --header "X-Api-Key: $API_KEY"

Revocation is immediate and cannot be undone. CryptoSwift prevents you from revoking the tenant's last valid API key; create and verify a replacement first. Repeating a request for an already revoked key is safe.

Security checklist

  • Keep Sandbox and Production keys separate.
  • Use a secrets manager and restrict which workloads can read each key.
  • Prefer short-lived keys where your operational process supports renewal.
  • Rotate keys after suspected exposure and as part of your normal security schedule.
  • Redact the X-Api-Key header and API key list responses from logs and traces.

Next steps