shareyourthoughtswith.me

API keys

Create, view, disable, and delete API keys at /admin/api-keys.

Lifecycle

Storage

Stored fields per key:

The raw secret is never persisted. Rotating SYTWM_API_KEY_PEPPER invalidates every existing key — only do this if a compromise is suspected.

Scopes

A future release may add finer-grained scopes (per-post, per-event-type).