/api/v1/businesses/:businessId/api-keys
auth: jwt (administrator)Generate a new static API key for on-premise agents (Sage 100/300/200 Evolution, Amicus). Stores SHA-256(rawKey) + an 8-char prefix; returns the raw 64-hex-char key exactly once. Optional scope binds the key to one AccountingProviderType; optional locationId scopes it to one Location (validated against the business). Fires API_KEY_CREATED.
handlers: ApiKeyController.create
| name | required | default | description |
|---|---|---|---|
businessId pathuuid | yes | — | Target business UUID. Administrator bypass via requireBusinessAccess. |
label bodystring | yes | — | Operator-facing label (1..200 chars). |
scope bodyAccountingProviderType | no | — | Bind to a single provider (sage100, sage300, sage200evolution, amicus, ...). Null/omitted = unscoped. |
locationId bodyuuid | no | — | Multi-location (TAXCORE-246) — scope the key to one Location. Validated against the business; mismatch returns 422 LOCATION_NOT_FOUND. |
APIResponseDataObject<CreateApiKeyResponse>APIErrorAPIError/api/v1/businesses/:businessId/api-keys
auth: jwt (administrator)List all API keys for a business (active + revoked). Raw secret is never returned — only label, prefix, scope, locationId, createdAt, lastUsedAt, revokedAt.
handlers: ApiKeyController.list
| name | required | default | description |
|---|---|---|---|
businessId pathuuid | yes | — | Target business UUID. |
APIResponseDataList<ApiKeyDTO>APIError/api/v1/businesses/:businessId/api-keys/:keyId
auth: jwt (administrator)Soft-revoke an API key (sets RevokedAt). Idempotent — re-calling on an already-revoked key is a no-op. Fires API_KEY_REVOKED on first revocation.
handlers: ApiKeyController.revoke
| name | required | default | description |
|---|---|---|---|
businessId pathuuid | yes | — | Target business UUID. |
keyId pathuuid | yes | — | ApiKeys.ApiKeyId to revoke. |
voidAPIErrorAPIError