How Do I Create And Use An API Key?
An API key lets you publish to OxyPages from a script, a CI job or an AI agent instead of the dashboard. Create one under Profile, API Keys. Every plan has API access, including Free.
Updated
An API key lets something other than you publish a website: a build script, a CI job, or an AI agent. It does the same thing the dashboard does, through a request instead of a browser.
Every plan has API access, including Free. The only requirement is a verified email address.
Create One
- Go to Profile, then API Keys
- Create a key and give it a name you will recognise later
- Copy it immediately
The key starts with oxy_ and is shown once. We store only a hash of it,
so if you lose it nobody can recover it for you. Create a new one and delete
the old.
Find Your Site Id
Most calls need to know which website to publish into. The id is in the site's
address in your dashboard, and it is also returned by GET /v1/sites.
Your site id is not a secret. Your API key is.
Publish With It
Send your files as a ZIP to the deployments endpoint with the key in an
Authorization: Bearer header. Everything in the ZIP becomes the website, and
the same rules apply as any other publish: there must be an index.html at
the top, each HTML page can be up to 5 MB, each other file up to
25 MB, and a ZIP up to 100 MB.
A successful call creates a new version, exactly like publishing from the dashboard, so your version history stays complete whichever way you publish.
Keep It Safe
A key can publish to your websites, so treat it like a password.
- Store it in your CI provider's secret store, never in your repository
- Use a separate key per place that needs one, so you can revoke just that one
- Delete any key you are not using
If a key is exposed, delete it in Profile, then API Keys. Deleting takes effect immediately, and anything using it will stop working, so create the replacement first.
What Uses This
- Deploying from GitHub on every push
- Publishing from an AI agent
- Your own scripts, through the REST API