API keys, the API playground and webhooks
Updated 3 min read
API keys are for calling the account API directly. You do not need one to use a proxy: proxies authenticate with their own username and password, or the IP allowlist. All three tools below sit under Tools in the dashboard side menu.
Create a key
You need a confirmed email address first.
- Open Tools > API keys.
- Click Generate new key. The new pair appears in the list as an API key and an API secret.
- Send both with every call, in the
X-Api-KeyandX-Api-Secretheaders.
A key acts as you. It is not limited to reading: anything you can do in the dashboard, including ordering and spending balance, a key can do too. Treat the secret like your password, and use one key per integration so you can retire one without touching the others.
Retire a key
Click Delete on its row and confirm with Delete key. Anything using it stops working at once, and a deleted key cannot be restored. Do this straight away if a secret ends up in a repository, a log or a chat.
Try calls before you code them
Tools > API playground lists a selection of the API's endpoints in groups: access, account, billing, orders and proxies. Pick one, fill in the request, and click Send request. These are real calls made as you, against your account. Reads are safe to explore; a write does what it says. Writes such as placing an order, starting a deposit or deleting a key ask you to confirm with Send anyway; others, such as updating the account or creating a key, are sent straight away.
Copy cURL snippet gives you the same call for a terminal, with Authorization: Bearer **** in place of a credential. Replace that line with your X-Api-Key and X-Api-Secret headers.
Get told instead of polling
Tools > Webhooks posts to your endpoint when something changes on the account, such as a proxy's status changing (for example when it becomes active or expires), bandwidth being added, or an incident or maintenance affecting your proxies.
- Click Add webhook, enter the Endpoint URL, and click Add webhook in the form.
- Copy the Signing secret when it is shown; that is the only time it is shown. Use it to check that deliveries really come from us.
- Send test event checks your endpoint. Show deliveries lists recent attempts; open a failed one and click Retry this delivery to send it again.
Lost the secret? Open the webhook and use Rotate secret. The old secret stops working at once, so deliveries fail your signature check until your endpoint uses the new one.
Questions about a specific endpoint go to support@proxyhive.io. Never paste a key's secret into the message.