Filodos

API key management

Create, list, and revoke organization API keys programmatically. All three endpoints need an administrator sign-in — API keys cannot manage themselves. Part of the documentation.

POST/api-keys

Creates a key for the administrator's own organization and returns the value once — store it at once, only the hash is kept afterwards. Valid scopes: devices:read, trips:read, events:read, telemetry:read, scores:read, drivers:read, positions:read, reports:read. Blank names, unknown scopes, and empty scope lists read 422.

curl -X POST https://filodos.gr/filodos-dashboard/api/scoring/api-keys \
  -H "Authorization: Bearer eyJhbGciOi…" \
  -H 'Content-Type: application/json' \
  -d '{"name": "SoftOne feed", "scopes": ["devices:read", "trips:read", "events:read"]}'

{"id": 3, "name": "SoftOne feed", "prefix": "filodos_6633",
 "scopes": ["devices:read", "trips:read", "events:read"],
 "created_at": "2026-10-05T08:00:00+00:00",
 "last_used_at": null, "revoked_at": null,
 "api_key": "filodos_6633dd4e…"}

GET/api-keys

Lists the organization's keys, newest first — same shape as above without the api_key value. Revoked keys stay listed with revoked_at set, and each use updates last_used_at.

curl https://filodos.gr/filodos-dashboard/api/scoring/api-keys \
  -H "Authorization: Bearer eyJhbGciOi…"

DELETE/api-keys/{id}

Revokes one key of the administrator's organization. Feeds using it read 401 from that moment. Another org's key id reads 404. There is no un-revoke — create a new key instead.

curl -X DELETE https://filodos.gr/filodos-dashboard/api/scoring/api-keys/3 \
  -H "Authorization: Bearer eyJhbGciOi…"

{"id": 3, "revoked": true}