Skip to main content

/api-key

Endpoint

/api-key

Overview

Returns the dashboard member's API key using HTTP Basic authentication.

Authentication

  • HTTP Basic Auth header with dashboard username:password

Permissions

  • Any existing dashboard user account can access this endpoint.
  • Locked users are rejected.
  • Brute-force protection is applied before password verification.

Request Parameters

This endpoint does not use query parameters. Provide credentials through the Authorization: Basic ... header.

Examples

Example 1: Read API key with cURL

curl -u "admin@example.com:YOUR_PASSWORD" \
https://your-server.com/api-key

Example 2: Read API key with explicit header

curl \
-H "Authorization: Basic BASE64(username:password)" \
https://your-server.com/api-key

Response

Success Response

0123456789abcdef0123456789abcdef

Response Fields

FieldTypeDescription
(raw body)StringThe member's API key.

Error Responses

Status Code: 401 Unauthorized

-1

Returned when credentials are missing, invalid, blocked by brute-force protection, or the user is locked.

Status Code: 500 Internal Server Error

Server Error

Returned if brute-force status lookup fails.

Behavior

  • Parses HTTP Basic credentials from the request.
  • Checks login brute-force state before password verification.
  • Verifies the password hash for the provided username.
  • Updates last_login for the member on success.
  • Returns the raw API key string, not JSON.

Limitations

  • This endpoint only supports HTTP Basic authentication.
  • Response body is plain text, not JSON.
  • Locked users cannot retrieve their API key through this route.
Implementation details

Database Collections

CollectionUsed forData touched by this endpoint
countly.membersCredential validation and API key sourceReads member credentials and returns api_key; updates last_login on success.
countly.failed_loginsBrute-force protection stateReads and resets failed-login state through the brute-force utility flow.