Skip to content
PacSpace
Talk to us

API keys

Create, list, rotate, disable, and delete the keys your integration writes with, from the dashboard routes.

An API key is what your integration sends as x-api-key to write entries and read records. The dashboard under Settings, Developer, API keys does everything below; these are the routes it calls.

Every route here needs a dashboard session cookie (-b pacspace-dashboard-cookies.txt). A POST or DELETE made with the cookie also sends X-Pacspace-CSRF: 1 and Origin: https://app.pacspace.io; without them the answer is 403. Routes that make, rotate, disable, or delete a key take the admin or manager role; any member can read.

Base URL: https://app.pacspace.io

http
POST https://app.pacspace.io/dashboard/api-keys

Create a key

A key for the evaluation harness that writes each run's record, in Sandbox:

bash
curl -X POST https://app.pacspace.io/dashboard/api-keys \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Eval harness",
    "environment": "sandbox"
  }'
FieldRequiredRule
nameYesUp to 255 characters. Dashboard is the name of the key the dashboard itself records through; a new key under that name is refused with 409 API_KEY_NAME_RESERVED.
environmentYessandbox or production. A sandbox key starts pk_test_ and writes to your Sandbox; a production key starts pk_live_ and writes to Production. A request that names neither is refused with 400 and "Choose an environment, sandbox or production. Whichever you choose is where it writes."

Answer 201 Created

json
{
  "success": true,
  "data": {
    "id": "cmw4k2n9x0001s6017h4qz8ma",
    "name": "Eval harness",
    "key": "pk_test_PUBLIC.SECRET",
    "environment": "sandbox",
    "lastUsedAt": null,
    "disabledAt": null,
    "createdAt": "2026-10-05T13:52:18.102Z",
    "updatedAt": "2026-10-05T13:52:18.102Z"
  },
  "message": "API key created successfully"
}

key is shown once, here. It is the whole value your integration sends; store it where your secrets live. No later answer carries it.

List keys

bash
curl "https://app.pacspace.io/dashboard/api-keys?page=1&limit=10" \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Environment: sandbox"

Answer 200 OK

json
{
  "success": true,
  "data": {
    "data": [
      {
        "id": "cmw4k2n9x0001s6017h4qz8ma",
        "name": "Eval harness",
        "environment": "sandbox",
        "lastUsedAt": "2026-10-05T14:09:47.410Z",
        "disabledAt": null,
        "createdAt": "2026-10-05T13:52:18.102Z",
        "updatedAt": "2026-10-05T13:52:18.102Z"
      }
    ],
    "pagination": { "page": 1, "limit": 10, "total": 1, "totalPages": 1 }
  },
  "message": "API keys retrieved successfully"
}

The list follows the dashboard's environment switch, sent as X-Environment: sandbox or production: it shows that environment's keys, and with no header it shows every key. A key made before every key was given an environment shows as Production, which is where it writes. The list is paged, 10 to a page by default and at most 100.

Get one key

bash
curl https://app.pacspace.io/dashboard/api-keys/cmw4k2n9x0001s6017h4qz8ma \
  -b pacspace-dashboard-cookies.txt

The answer carries the same fields as a row of the list, with "API key retrieved successfully". A key's secret is never in it.

Rotate a key

Issues a new secret for the same key. The id, the part before the dot, and the environment stay; the old secret stops working at once.

bash
curl -X POST https://app.pacspace.io/dashboard/api-keys/cmw4k2n9x0001s6017h4qz8ma/regenerate \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io"

Answer 201 Created

json
{
  "success": true,
  "data": {
    "id": "cmw4k2n9x0001s6017h4qz8ma",
    "name": "Eval harness",
    "environment": "sandbox",
    "lastUsedAt": "2026-10-05T14:09:47.410Z",
    "disabledAt": null,
    "createdAt": "2026-10-05T13:52:18.102Z",
    "updatedAt": "2026-10-06T09:12:40.881Z",
    "key": "pk_test_PUBLIC.NEW_SECRET"
  },
  "message": "API key regenerated successfully"
}

Update the integration's configuration before the next write. Entries written with the old secret stay attributed to this key, and nothing in the record changes.

The Dashboard key has no secret to rotate, because the dashboard records through it directly. Rotating it is refused with 409 API_KEY_DASHBOARD_NOT_ROTATABLE; disable it or delete it instead.

Disable or enable a key

bash
curl -X POST https://app.pacspace.io/dashboard/api-keys/cmw4k2n9x0001s6017h4qz8ma/toggle \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io"

Each call flips the key. The answer carries the key with disabledAt set to the moment it was disabled, or null once enabled again, with "API key status updated successfully". A disabled key is refused with 401 on every records route.

Delete a key

bash
curl -X DELETE https://app.pacspace.io/dashboard/api-keys/cmw4k2n9x0001s6017h4qz8ma \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io"

A key that has never written an entry is deleted, and the answer is data: null with "API key deleted successfully". A key that has written entries is not, because the entries name it:

json
{
  "success": false,
  "error": {
    "statusCode": 409,
    "message": "Entries were written with it, so it stays on record. Disable it instead; what it wrote stays attributed to it.",
    "timestamp": "2026-10-06T09:20:03.554Z",
    "path": "/dashboard/api-keys/cmw4k2n9x0001s6017h4qz8ma",
    "code": "API_KEY_IN_USE"
  }
}

Disable it. It stops writing at once, and every entry it wrote keeps saying which key wrote it.

Key format

text
pk_test_PUBLIC.SECRET
pk_live_PUBLIC.SECRET

The part before the dot identifies the key and says which environment it writes to. The part after the dot is the secret, shown once and never logged. Send the whole value as x-api-key.

Routes

RouteMethodRole
/dashboard/api-keysPOSTadmin, manager
/dashboard/api-keysGETany member
/dashboard/api-keys/:idGETany member
/dashboard/api-keys/:id/regeneratePOSTadmin, manager
/dashboard/api-keys/:id/togglePOSTadmin, manager
/dashboard/api-keys/:idDELETEadmin, manager