API Keys
List API keys
GET /api/keysReturns all active (non-revoked) API keys for your account. Key values are masked after creation - only the tp_ prefix plus the first 8 characters is stored for identification.
Response 200 OK
[
{
"id": "3f8b2c1d-9e0a-4b5c-8d7e-6f5a4b3c2d10",
"name": "CI/CD Pipeline",
"prefix": "tp_a1b2c3d4",
"createdAt": "2025-01-05T09:00:00Z",
"lastUsedAt": "2025-02-14T15:30:00Z"
}
]Create API key
POST /api/keysCreates a new API key. The full key value is only returned once at creation time.
Request body
| Field | Type | Required | Description |
|---|---|---|---|
name | string | Yes | A descriptive name for the key |
Response 201 Created
{
"id": "5a7c9e1b-3d2f-4a6b-8c0d-1e2f3a4b5c60",
"name": "GitHub Actions",
"prefix": "tp_a1b2c3d4",
"key": "tp_a1b2c3d4e5f60718293a4b5c6d7e8f90"
}Save the key value immediately - it cannot be retrieved again.
Revoke API key
DELETE /api/keys/:idPermanently revokes an API key. Any integrations using this key will stop working.
Response 200 OK
{ "success": true }Domains
Register and verify domain ownership through the TurboPentest API. Verify a root domain once and every subdomain is automatically covered for pentesting.
Integrations API
Manage your Slack and Jira integrations through the TurboPentest API, listing configured integrations with sensitive tokens masked in every response.