API Keys
Create and manage scoped API keys for programmatic access to the Boltly API. The secret is shown only once at creation — store it securely.
/v1/api-keys Create key
Create a scoped API key. The secret key is returned only once in this response — store it securely, it cannot be retrieved again.
Parameters
name string required Display name for the key. Max 255 characters.
scopes array required Permission scopes granted to this key (at least one). Valid scopes: contacts.read, contacts.write, contacts.manage, broadcasts.read, broadcasts.create, broadcasts.send, templates.read, templates.create, templates.manage, inbox.read, inbox.write.
expires_at string Optional expiry timestamp in RFC3339 format. Must be in the future. Omit for a non-expiring key.
Request
curl -X POST https://api.boltly.online/v1/api-keys \
-H "X-API-Key: $API_KEY" \
-H "Content-Type: application/json" \
-d '{
"name": "CI integration",
"scopes": ["contacts.read", "broadcasts.send"],
"expires_at": "2027-01-01T00:00:00Z"
}' Response
{
"data": {
"id": "5f6a7b8c-...",
"name": "CI integration",
"secret_key": "blt_live_9x8w7v...",
"prefix": "blt_live_9x8w",
"scopes": ["contacts.read", "broadcasts.send"],
"expires_at": "2027-01-01T00:00:00Z",
"created_at": "2026-04-03T12:00:00Z"
}
} /v1/api-keys List keys
List all API keys for your organization. Secret values are never returned — only the display prefix.
Parameters
— No parameters. The organization is derived from your API key.
Request
curl https://api.boltly.online/v1/api-keys \
-H "X-API-Key: $API_KEY" Response
{
"data": [
{
"id": "5f6a7b8c-...",
"name": "CI integration",
"prefix": "blt_live_9x8w",
"scopes": ["contacts.read", "broadcasts.send"],
"last_used_at": "2026-04-03T14:20:00Z",
"expires_at": "2027-01-01T00:00:00Z",
"created_by": "4d5e6f7a-...",
"created_at": "2026-04-03T12:00:00Z",
"is_active": true
}
],
"meta": { "total": 1 }
} /v1/api-keys/{id} Delete key
Revoke and delete an API key. Requests using the key fail immediately after deletion.
Parameters
id string required API key ID.
Request
curl -X DELETE https://api.boltly.online/v1/api-keys/5f6a7b8c-... \
-H "X-API-Key: $API_KEY" Response
{
"data": {
"deleted": true
}
}