This route resets a provider’s API key and is accessible to both providers and admins.
Reset Provider API Key
This endpoint generates a new API key for a provider, immediately invalidating the old one. A notification email with the new key is sent to the provider's registered address. The new key is also returned directly in the API response for immediate use.
This is a dual-role endpoint:
- Admins can reset a provider’s API key but does not allow viewing the API key for any provider.
- Providers can only reset their own API key using their current key for authentication.
Endpoint
PATCH /api/v1/providers/{pro_id}/api-keyAuthentication
| Type | Required | Location | Description |
|---|---|---|---|
| Admin Key OR Provider Key | true | Header | The key must be sent as x-api-key: YOUR_API_KEY. |
The behavior of this endpoint depends on the type of key provided.
URL Parameters
| Parameter | Type | Required | Description |
|---|---|---|---|
pro_id | string | true | The unique ID of the provider whose API key is to be reset. For providers, this must be their own ID. |
Request
This endpoint does not require a request body.
Example Requests
As an Administrator
This request resets the API key for the specified provider. Replace PROVIDER_ID_TO_RESET and YOUR_ADMIN_KEY.
curl -X PATCH 'https://offers.dataoorts.com/api/v1/providers/PROVIDER_ID_TO_RESET/api-key' \
-H 'x-api-key: YOUR_ADMIN_KEY'As a Provider (Self-Reset)
This request resets the authenticated provider's own API key. The pro_id in the URL must match the ID associated with the PROVIDER_OLD_API_KEY.
curl -X PATCH 'https://offers.dataoorts.com/api/v1/providers/YOUR_OWN_PRO_ID/api-key' \
-H 'x-api-key: YOUR_PROVIDER_OLD_API_KEY'If you are unable to reset the API key, please contact us at [email protected]
Responses
✅ Success Response (200 OK)
Returned when the API key is successfully reset. The response includes the new key. This is the only time the new key will be shown via the API, so it must be saved securely.
Body
{
"status": "Success",
"message": "API key for provider 'PRO_154486369896353' successfully reset, Please save safely the new api key.",
"new_api_key": "PRO_456538656986986355"
}❌ Error Response (401 Unauthorized)
Returned if the x-api-key header is missing or the provided key is invalid and does not match any user.
Body
{
"error": "Unauthorized: Invalid API key."
}More than three failed authentication attempts will result in a permanent IP block.
❌ Error Response (403 Forbidden)
This error is specific to Providers. It is returned when a provider attempts to reset the API key for an account other than their own or using invalid pro_id credentials.
Body
{
"error": "Forbidden",
"details": "You can only reset your own API key."
}❌ Error Response (404 Not Found)
This error is specific to Admins. It is returned if no provider account exists with the pro_id provided in the URL.
Body
{
"error": "Not Found",
"details": "No provider found with ID 'PRO_6985333557896254853695'."
}❌ Error Response (500 Internal Server Error)
Returned for database errors or other unexpected issues on the server during the reset process.
Body
{
"error": "Database error occurred",
"details": "Specific error message from the database driver."
}