Documentation / API reference

API keys

Create, list and revoke the Bearer keys clients use.

List keys

GET/v1/keysBearerTry it →

Returns { keys: [{ id, label, key, lastUsedAt }] }.

Create a key

POST/v1/keysBearerTry it →
curl -X POST http://localhost:8787/v1/keys \
  -H "Authorization: Bearer $PYRUS_KEY" \
  -H "Content-Type: application/json" \
  -d '{"label":"telegram bot"}'

Revoke keys

DELETE/v1/keys/:idBearer
POST/v1/keys/revoke-allBearer

Revocation takes effect immediately — whatever is using the key stops working.

revoke-all kills the browser panel's own key too. The panel re-credentials itself automatically; a script would need to fetch a new key.
Both revocation routes are curl-only in the playground: they cut off access, including possibly your own session. See what the playground restricts.