Manage API keys
Create, rotate, list, and revoke tenant API keys safely.
CryptoSwift tenant API keys authenticate Client API requests through the X-Api-Key header. Manage keys from a trusted backend or an authenticated administrator session. Never expose them in browser or mobile application code.
The API key management endpoints are available at /tenant/me/api-keys in both Sandbox and Production. The two environments use separate credentials.
List API keys
curl --location 'https://api-dev.cryptoswift.eu/tenant/me/api-keys' \ --header "X-Api-Key: $API_KEY"
Each record includes id, apiKey, expiresAt, createdAt, and revokedAt. A key is no longer valid after it expires or is revoked. Treat list responses as sensitive because they contain usable key material.
Create a key
Create a key without an expiry:
curl --request POST 'https://api-dev.cryptoswift.eu/tenant/me/api-keys' \
--header "X-Api-Key: $API_KEY" \
--header 'Content-Type: application/json' \
--data '{}'
To create a short-lived key, supply a future ISO 8601 timestamp:
{
"expiresAt": "2030-01-31T23:59:59.000Z"
}
Store the returned apiKey in a secrets manager immediately. Do not commit it, log it, or send it to a frontend.
Rotate a key
Use overlapping rotation so integrations do not lose access:
- Create a new key.
- Store it in your secret manager and deploy it to every service that calls CryptoSwift.
- Verify requests with the new key in the relevant environment.
- Revoke the old key.
Revoke a key
curl --request DELETE 'https://api-dev.cryptoswift.eu/tenant/me/api-keys/{apiKeyId}' \
--header "X-Api-Key: $API_KEY"
Revocation is immediate and cannot be undone. CryptoSwift prevents you from revoking the tenant's last valid API key; create and verify a replacement first. Repeating a request for an already revoked key is safe.
Security checklist
- Keep Sandbox and Production keys separate.
- Use a secrets manager and restrict which workloads can read each key.
- Prefer short-lived keys where your operational process supports renewal.
- Rotate keys after suspected exposure and as part of your normal security schedule.
- Redact the
X-Api-Keyheader and API key list responses from logs and traces.