Boltly Boltly / Docs
Docs / Developer Tools / API Keys

API Keys

Create and manage scoped API keys for programmatic access to the Boltly API. The secret is shown only once at creation — store it securely.

POST /v1/api-keys

Create key

Create a scoped API key. The secret key is returned only once in this response — store it securely, it cannot be retrieved again.

Parameters

name string required

Display name for the key. Max 255 characters.

scopes array required

Permission scopes granted to this key (at least one). Valid scopes: contacts.read, contacts.write, contacts.manage, broadcasts.read, broadcasts.create, broadcasts.send, templates.read, templates.create, templates.manage, inbox.read, inbox.write.

expires_at string

Optional expiry timestamp in RFC3339 format. Must be in the future. Omit for a non-expiring key.

Request

cURL
curl -X POST https://api.boltly.online/v1/api-keys \
  -H "X-API-Key: $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "CI integration",
    "scopes": ["contacts.read", "broadcasts.send"],
    "expires_at": "2027-01-01T00:00:00Z"
  }'

Response

JSON
{
  "data": {
    "id": "5f6a7b8c-...",
    "name": "CI integration",
    "secret_key": "blt_live_9x8w7v...",
    "prefix": "blt_live_9x8w",
    "scopes": ["contacts.read", "broadcasts.send"],
    "expires_at": "2027-01-01T00:00:00Z",
    "created_at": "2026-04-03T12:00:00Z"
  }
}

GET /v1/api-keys

List keys

List all API keys for your organization. Secret values are never returned — only the display prefix.

Parameters

—

No parameters. The organization is derived from your API key.

Request

cURL
curl https://api.boltly.online/v1/api-keys \
  -H "X-API-Key: $API_KEY"

Response

JSON
{
  "data": [
    {
      "id": "5f6a7b8c-...",
      "name": "CI integration",
      "prefix": "blt_live_9x8w",
      "scopes": ["contacts.read", "broadcasts.send"],
      "last_used_at": "2026-04-03T14:20:00Z",
      "expires_at": "2027-01-01T00:00:00Z",
      "created_by": "4d5e6f7a-...",
      "created_at": "2026-04-03T12:00:00Z",
      "is_active": true
    }
  ],
  "meta": { "total": 1 }
}

DELETE /v1/api-keys/{id}

Delete key

Revoke and delete an API key. Requests using the key fail immediately after deletion.

Parameters

id string required

API key ID.

Request

cURL
curl -X DELETE https://api.boltly.online/v1/api-keys/5f6a7b8c-... \
  -H "X-API-Key: $API_KEY"

Response

JSON
{
  "data": {
    "deleted": true
  }
}