API reference

API keys

Keys are managed by owners and admins in Kweko (Settings → Developers). With a key you can only ask who you are.

Who am I

GET/v1/api-keys/whoamiNo scope needed

Works with every key, whatever its scopes. Use it to check a key after you set it up.

Response
{
  "object": "api_key",
  "id": "key_01j8z6q3m7e2x9c4v5b6n7p8r0",
  "name": "Website form",
  "scopes": ["contacts:write", "leads:write"],
  "workspace": { "id": "ws_01j8z5w2k4h6j8m0n2p4r6t8v0", "slug": "acme" }
}

Key management

These endpoints serve Settings → Developers. They accept only signed-in owners and admins; an API key or app token gets permission_denied, so a leaked key can never create more keys.

GET/v1/api-keysKweko app only
POST/v1/api-keysKweko app only
GET/v1/api-keys/scopesKweko app only
GET/v1/api-keys/{id}Kweko app only
PATCH/v1/api-keys/{id}Kweko app only
POST/v1/api-keys/{id}/rotateKweko app only
POST/v1/api-keys/{id}/revokeKweko app only
GET/v1/api-keys/{id}/requestsKweko app only

The key object they return:

FieldDescription
id, objectkey_…, "api_key"
name, descriptionName (2 to 60 characters, unique in the workspace) and an optional description
prefix, last4The start and the last 4 characters of the secret, to recognize it
scopesThe granted scopes
ip_allowlistAllowed IPs and CIDR ranges, empty for any
expires_atWhen it expires, or null
statusactive, rotating (the old secret still works during the 24 hour overlap), expired or revoked
rotating_untilEnd of the overlap after a rotation
created_byWho created it
last_used_at, last_used_ipLast use
created_at, revoked_at