# Keys for your users

> Keys limited to one of your users, safe to hand to their own app: make, list and revoke them.

Keys limited to one of your users, safe to hand to their own app: make, list and revoke them. This page is generated from the API's own spec, so it says exactly what the API does.

## Make a key limited to one of your users

`POST /v1/keys`

A key that reaches only the user this call names (X-Geniffy-Space, or space in the body), and nothing
else: safe to hand to that user's own app or device. It is shown once. Made only with a key that reaches
your whole account; a limited key can't make keys.

| Parameter | In | Type | Description |
| --- | --- | --- | --- |
| `X-Geniffy-Space` | header | string | One of your own users, for every call this client makes. Leave it out for your own memory; a blank one is refused. (up to 128 characters) |

**Body** (application/json)

| Field | Type | | Description |
| --- | --- | --- | --- |
| `name` | string | optional | What to call it, such as the app it is for (up to 100 characters) |
| `rpm` | integer | optional | Requests a minute it may make. Left out, 600 (at least 1; at most 600) |
| `expires_at` | string | optional | When it stops working by itself: an ISO 8601 time, or a date, which it works through (UTC). Left out, it works until revoked (up to 40 characters) |
| `space` | string | optional | One of your own users. Leave it out for your own memory; a blank one is refused. (up to 128 characters) |

**Returns** `201`

| Field | Type | | Description |
| --- | --- | --- | --- |
| `id` | integer | optional |  |
| `name` | string | optional |  |
| `space` | string | required | The one user it reaches |
| `key` | string | optional | The key itself: only when it is made, never again |
| `starts_with` | string | optional | Its first characters, to tell it apart in a list |
| `created_at` | string | optional |  |
| `last_used_at` | string | optional |  |
| `expires_at` | string | optional | When it stops working by itself; null: when revoked |
| `note` | string | optional |  |

## The keys limited to one of your users

`GET /v1/keys`

| Parameter | In | Type | Description |
| --- | --- | --- | --- |
| `space` | query | string | One of your own users. Leave it out for your own memory; a blank one is refused. (up to 128 characters) |
| `X-Geniffy-Space` | header | string | One of your own users, for every call this client makes. Leave it out for your own memory; a blank one is refused. (up to 128 characters) |

**Returns** `200`

| Field | Type | | Description |
| --- | --- | --- | --- |
| `keys` | array of KeyOut | required |  |

## Revoke a key limited to one of your users

`DELETE /v1/keys/{key_id}`

It stops at once. Erasing that user's space stops every key limited to it as well.

| Parameter | In | Type | Description |
| --- | --- | --- | --- |
| `key_id` | path | integer |  |
| `space` | query | string | One of your own users. Leave it out for your own memory; a blank one is refused. (up to 128 characters) |
| `X-Geniffy-Space` | header | string | One of your own users, for every call this client makes. Leave it out for your own memory; a blank one is refused. (up to 128 characters) |

**Returns** `200`

| Field | Type | | Description |
| --- | --- | --- | --- |
| `id` | integer | required |  |
| `space` | string | required |  |
| `revoked` | boolean | required |  |

Source: https://docs.geniffy.com/api/keys
