Developer API Documentation

Base URL: https://agenticrmai.app/api/v1/developer

Authentication: All endpoints require Laravel Sanctum token authentication via Authorization: Bearer {token} header.

Overview

The LoopBroker Developer API provides programmatic access to manage client API keys for your team. All operations are scoped to the authenticated user's current team, ensuring multi-tenant isolation.

Authentication

All API requests must include a valid Sanctum token in the Authorization header:

Authorization: Bearer your-sanctum-token-here

Endpoints

List Client Keys

GET /api/v1/developer/client-keys

Retrieve all client API keys for the authenticated user's current team.

Response Example:

{
  "success": true,
  "data": [
    {
      "id": 1,
      "name": "client-key-production",
      "abilities": ["*"],
      "last_used_at": "2026-08-13T10:30:00Z",
      "created_at": "2026-08-01T09:00:00Z"
    }
  ],
  "team": {
    "id": 42,
    "name": "Acme Corp"
  }
}

Create Client Key

POST /api/v1/developer/client-keys

Create a new client API key for the authenticated user's current team.

Request Body:

{
  "name": "production",
  "abilities": ["read", "write"]
}

Parameters:

Response Example:

{
  "success": true,
  "data": {
    "id": 2,
    "name": "client-key-production",
    "abilities": ["read", "write"],
    "token": "1|abc123def456...",
    "created_at": "2026-08-13T12:00:00Z"
  },
  "message": "Client key created successfully. Store the token securely - it will not be shown again."
}

⚠️ Important: The token field contains the plain-text API key. Store it securely - it will never be displayed again after creation.

Revoke Client Key

DELETE /api/v1/developer/client-keys/{tokenId}

Permanently revoke a client API key. The key will be immediately invalidated.

URL Parameters:

Response Example (Success):

{
  "success": true,
  "message": "Client key revoked successfully."
}

Response Example (Not Found):

{
  "success": false,
  "message": "Client key not found or does not belong to your team."
}

Error Handling

All endpoints return standard HTTP status codes:

Rate Limiting

API requests are subject to Laravel's default rate limiting. Monitor the following response headers:

Example Usage

Here's a complete example using cURL:

# List all client keys
curl -X GET https://agenticrmai.app/api/v1/developer/client-keys \
  -H "Authorization: Bearer your-sanctum-token" \
  -H "Accept: application/json"

# Create a new client key
curl -X POST https://agenticrmai.app/api/v1/developer/client-keys \
  -H "Authorization: Bearer your-sanctum-token" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json" \
  -d '{"name": "production", "abilities": ["*"]}'

# Revoke a client key
curl -X DELETE https://agenticrmai.app/api/v1/developer/client-keys/1 \
  -H "Authorization: Bearer your-sanctum-token" \
  -H "Accept: application/json"

Need Help? Contact your team administrator or refer to the Laravel Sanctum documentation for more information about token-based authentication.