Skip to main content
API keys — project-scoped credentials for relay pub/sub auth. Reach it as client.apiKeys on a QumoClient.

list

Lists a project’s API keys. Secrets are never returned. Types: APIKey

create

Creates an API key. suffix narrows the key’s broadcast prefix beneath the project’s; mode fixes whether its credentials publish or subscribe. The returned secret is shown only once.

revoke

Revokes an API key. Credentials already minted keep working until they expire.

regenerate

Issues a new secret for an API key, invalidating the old one. The new secret is shown only once.

getUsage

Request volume and latency for one API key, bucketed by time and response category. Types: APIKeyUsage

listIPAllowlists

Direct (non-identity) key IP allowlists. A direct key with entries is restricted to those CIDRs; Identity Tokens are covered by their Identity’s allowlist (ipAllowlists.*) and return an empty list here. See ADR 0025. Types: APIKeyIPAllowlist

createIPAllowlist

Restricts a direct API key to a CIDR range; once any entry exists, other addresses are refused. Types: APIKeyIPAllowlist

deleteIPAllowlist

Removes one IP allowlist entry from a direct API key.