API referenceKeys and access
Exchange an app code for a key
Final step of Sign in with GridRouter: exchange the one-time code and its PKCE code_verifier for a user-controlled key with call/run scopes and any credit limit the user set.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
curl -X POST "https://example.com/v1/auth/keys" \ -H "Content-Type: application/json" \ -d '{ "code": "string", "code_verifier": "stringstringstringstringstringstringstrings" }'{ "object": "auth_key", "key": "string", "key_id": "string", "scopes": [ "*" ], "limit_micro": 0, "limit_reset": "day", "app_name": "string", "expires_at": "2019-08-24T14:15:22Z"}Authorize a third-party app POST
Consent step of Sign in with GridRouter (OAuth PKCE, S256): a signed-in member approves an app and gets a one-time code (10 minutes) to redirect back with.
List vendor credentials GET
Your own vendor keys (BYOK) stored for this org: provider, slot, label, field names, the key's last four characters and its last test result. Secrets are write-only and never returned.