Trade a pairing code for a key
POST/keys/exchange
The site presents the code issued in the dashboard and receives its own API key. Server-to-server, with no prior credential — the code is the credential, single use.
The key comes bound to the site (siteId) with the permissions of a connected site. A code
that does not exist, has expired, was already used or was issued for another address, and
an invalid body, all get the same answer, 401 pairing_invalid: from outside, one case
cannot be told from another. Limited to 20 attempts every 10 minutes per IP.
Request
Responses
- 201
- 401
- 429
Key issued.
Missing, malformed, unknown or revoked token (authentication), or a suspended
account (tenant_inactive).
Rate limit exceeded (rate_limit).
Response Headers
Seconds to wait before retrying.
Which rate limit category applied — send, media or default.
Which bucket the other headers describe — key (the API key), session (the dashboard) or account (the account ceiling).
Request ceiling for this category in the current window.
Requests left in the current window.