API reference
API keys
Keys are managed by owners and admins in Kweko (Settings → Developers). With a key you can only ask who you are.
Who am I
GET
/v1/api-keys/whoamiNo scope neededWorks with every key, whatever its scopes. Use it to check a key after you set it up.
Response
{
"object": "api_key",
"id": "key_01j8z6q3m7e2x9c4v5b6n7p8r0",
"name": "Website form",
"scopes": ["contacts:write", "leads:write"],
"workspace": { "id": "ws_01j8z5w2k4h6j8m0n2p4r6t8v0", "slug": "acme" }
}Key management
These endpoints serve Settings → Developers. They accept only signed-in owners and admins; an API key or app token gets permission_denied, so a leaked key can never create more keys.
GET
/v1/api-keysKweko app onlyPOST
/v1/api-keysKweko app onlyGET
/v1/api-keys/scopesKweko app onlyGET
/v1/api-keys/{id}Kweko app onlyPATCH
/v1/api-keys/{id}Kweko app onlyPOST
/v1/api-keys/{id}/rotateKweko app onlyPOST
/v1/api-keys/{id}/revokeKweko app onlyGET
/v1/api-keys/{id}/requestsKweko app onlyThe key object they return:
| Field | Description |
|---|---|
id, object | key_…, "api_key" |
name, description | Name (2 to 60 characters, unique in the workspace) and an optional description |
prefix, last4 | The start and the last 4 characters of the secret, to recognize it |
scopes | The granted scopes |
ip_allowlist | Allowed IPs and CIDR ranges, empty for any |
expires_at | When it expires, or null |
status | active, rotating (the old secret still works during the 24 hour overlap), expired or revoked |
rotating_until | End of the overlap after a rotation |
created_by | Who created it |
last_used_at, last_used_ip | Last use |
created_at, revoked_at |