Ex Extract API

Authentication

All authenticated endpoints require a Bearer token with your API key.

API key format

ext_live_<32 random characters>

Example prefix: ext_live_. Keys are generated with cryptographically secure random bytes.

Request header

Authorization: Bearer ext_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Getting an API key

Sign up at https://cyber.lerepop.lv/register, verify your email, then copy your key from the dashboard. It is shown in full only once. The API is blocked until email_verified_at is set on your account.

Key storage

  • We store only a bcrypt hash of your key — never the plaintext
  • The first 12 characters are stored as api_key_prefix for support identification
  • If you lose your key, call POST /api/v1/account/rotate-key or rotate it from the dashboard

Webhook secret

At registration you also receive webhook_secret — used to verify HMAC signatures on outgoing extraction webhooks. Store it alongside your API key.

X-Extract-Signature: sha256=<hex hmac of raw body>

Rate limiting

Default: 60 requests per minute per API key. Exceeding the limit returns 429 Too Many Requests.

Unauthenticated endpoints

EndpointDescription
GET /healthService health check
POST /webhooks/stripeStripe webhook (signed by Stripe)