API key management
Create, list, and revoke organization API keys programmatically. All three endpoints need an administrator sign-in — API keys cannot manage themselves. Part of the documentation.
POST/api-keys
Creates a key for the administrator's own organization and returns the value once — store it at once, only the hash is kept afterwards. Valid scopes: devices:read, trips:read, events:read, telemetry:read, scores:read, drivers:read, positions:read, reports:read. Blank names, unknown scopes, and empty scope lists read 422.
curl -X POST https://filodos.gr/filodos-dashboard/api/scoring/api-keys \
-H "Authorization: Bearer eyJhbGciOi…" \
-H 'Content-Type: application/json' \
-d '{"name": "SoftOne feed", "scopes": ["devices:read", "trips:read", "events:read"]}'
{"id": 3, "name": "SoftOne feed", "prefix": "filodos_6633",
"scopes": ["devices:read", "trips:read", "events:read"],
"created_at": "2026-10-05T08:00:00+00:00",
"last_used_at": null, "revoked_at": null,
"api_key": "filodos_6633dd4e…"}
GET/api-keys
Lists the organization's keys, newest first — same shape as above without the api_key value. Revoked keys stay listed with revoked_at set, and each use updates last_used_at.
curl https://filodos.gr/filodos-dashboard/api/scoring/api-keys \
-H "Authorization: Bearer eyJhbGciOi…"
DELETE/api-keys/{id}
Revokes one key of the administrator's organization. Feeds using it read 401 from that moment. Another org's key id reads 404. There is no un-revoke — create a new key instead.
curl -X DELETE https://filodos.gr/filodos-dashboard/api/scoring/api-keys/3 \
-H "Authorization: Bearer eyJhbGciOi…"
{"id": 3, "revoked": true}