X-API-Key header. Create keys in the Pioneer dashboard, then use the key management endpoints to list and revoke existing keys programmatically.
Create an API key
POST /create-api-key
Generates a new API key associated with your account. This endpoint is used by the Pioneer dashboard and requires a browser session. Calls authenticated with an existing API key are rejected with 403 Forbidden to prevent credential chaining.
Request body
string
required
A descriptive name to identify this key. Use names that reflect the key’s purpose or the service it belongs to, for example
"ci-pipeline" or "production-inference".string
The full API key value. This is the only time it is returned in plaintext — copy it immediately and store it somewhere secure such as a secrets manager or environment variable.
string
Unique identifier for the key. Use this ID when revoking the key.
string
The name you assigned to the key.
string
ISO 8601 timestamp of when the key was created.
string
Last digits of the generated key for display and identification.
string | null
Optional ISO 8601 expiration timestamp, or
null when the key does not expire.string
Team the key is bound to.
boolean
Whether Pioneer created a Stripe customer record during key creation.
List API keys
GET /list-api-keys
Returns all API keys associated with your account. Key values are masked in the response — only metadata such as name and creation date are returned.
object[]
Array of API key metadata objects.
number
Number of keys returned.
Revoke an API key
DELETE /delete-api-key
Permanently revokes an API key. Any requests using the revoked key will immediately receive 401 Unauthorized responses.
Request body
string
required
The unique ID of the key to revoke, as returned by
GET /list-api-keys.200 OK with a JSON success body.
boolean
Whether the key was revoked.
string | null
Human-readable status message.