Developer API Documentation
Base URL: https://agenticrmai.app/api/v1/developer
Authentication: All endpoints require Laravel Sanctum token authentication via Authorization: Bearer {token} header.
Overview
The LoopBroker Developer API provides programmatic access to manage client API keys for your team. All operations are scoped to the authenticated user's current team, ensuring multi-tenant isolation.
Authentication
All API requests must include a valid Sanctum token in the Authorization header:
Authorization: Bearer your-sanctum-token-here
Endpoints
List Client Keys
GET /api/v1/developer/client-keys
Retrieve all client API keys for the authenticated user's current team.
Response Example:
{
"success": true,
"data": [
{
"id": 1,
"name": "client-key-production",
"abilities": ["*"],
"last_used_at": "2026-08-13T10:30:00Z",
"created_at": "2026-08-01T09:00:00Z"
}
],
"team": {
"id": 42,
"name": "Acme Corp"
}
}
Create Client Key
POST /api/v1/developer/client-keys
Create a new client API key for the authenticated user's current team.
Request Body:
{
"name": "production",
"abilities": ["read", "write"]
}
Parameters:
name(required, string): A descriptive name for the keyabilities(optional, array): Array of permission strings. Defaults to["*"]for all permissions
Response Example:
{
"success": true,
"data": {
"id": 2,
"name": "client-key-production",
"abilities": ["read", "write"],
"token": "1|abc123def456...",
"created_at": "2026-08-13T12:00:00Z"
},
"message": "Client key created successfully. Store the token securely - it will not be shown again."
}
⚠️ Important: The token field contains the plain-text API key.
Store it securely - it will never be displayed again after creation.
Revoke Client Key
DELETE /api/v1/developer/client-keys/{tokenId}
Permanently revoke a client API key. The key will be immediately invalidated.
URL Parameters:
tokenId(required, integer): The ID of the token to revoke
Response Example (Success):
{
"success": true,
"message": "Client key revoked successfully."
}
Response Example (Not Found):
{
"success": false,
"message": "Client key not found or does not belong to your team."
}
Error Handling
All endpoints return standard HTTP status codes:
200 OK- Request successful201 Created- Resource created successfully401 Unauthorized- Invalid or missing authentication token404 Not Found- Resource not found or not accessible422 Unprocessable Entity- Validation errors
Rate Limiting
API requests are subject to Laravel's default rate limiting. Monitor the following response headers:
X-RateLimit-Limit- Maximum requests allowedX-RateLimit-Remaining- Requests remaining in current windowRetry-After- Seconds until rate limit resets (when limit exceeded)
Example Usage
Here's a complete example using cURL:
# List all client keys
curl -X GET https://agenticrmai.app/api/v1/developer/client-keys \
-H "Authorization: Bearer your-sanctum-token" \
-H "Accept: application/json"
# Create a new client key
curl -X POST https://agenticrmai.app/api/v1/developer/client-keys \
-H "Authorization: Bearer your-sanctum-token" \
-H "Content-Type: application/json" \
-H "Accept: application/json" \
-d '{"name": "production", "abilities": ["*"]}'
# Revoke a client key
curl -X DELETE https://agenticrmai.app/api/v1/developer/client-keys/1 \
-H "Authorization: Bearer your-sanctum-token" \
-H "Accept: application/json"
Need Help? Contact your team administrator or refer to the Laravel Sanctum documentation for more information about token-based authentication.