Authentication
All authenticated endpoints require a Bearer token with your API key.
API key format
ext_live_<32 random characters>
Example prefix: ext_live_. Keys are generated with cryptographically secure random bytes.
Request header
Authorization: Bearer ext_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Getting an API key
Sign up at https://cyber.lerepop.lv/register, verify your email,
then copy your key from the dashboard. It is shown in full only once.
The API is blocked until email_verified_at is set on your account.
Key storage
- We store only a bcrypt hash of your key — never the plaintext
- The first 12 characters are stored as
api_key_prefixfor support identification - If you lose your key, call
POST /api/v1/account/rotate-keyor rotate it from the dashboard
Webhook secret
At registration you also receive webhook_secret — used to verify HMAC signatures on
outgoing extraction webhooks. Store it alongside your API key.
X-Extract-Signature: sha256=<hex hmac of raw body>
Rate limiting
Default: 60 requests per minute per API key.
Exceeding the limit returns 429 Too Many Requests.
Unauthenticated endpoints
| Endpoint | Description |
|---|---|
GET /health | Service health check |
POST /webhooks/stripe | Stripe webhook (signed by Stripe) |