DocsGuidesAuthentication

Authentication

Kist has two credentials with different jobs: a short-lived session token for account actions, and a long-lived API key for programmatic proof operations.

Session tokens

Obtained by signing in or registering. They are short-lived (15 minutes) and used for account operations such as creating and listing API keys, and credit top-ups.

POST/auth/registerCreate an account with email + password (12+ chars)
POST/auth/loginExchange credentials for a session token

API keys

API keys (they look like kist_live_…) authorize metered proof operations. Send them as a Bearer token on every API request. Keys are hashed at rest and shown only once at creation.

header — bearerbash
# Every metered request carries your keyAuthorization: Bearer <KIST_API_KEY>
Treat keys like passwords

If a key leaks, revoke it in the console immediately. Revocation is instant.

Managing keys

POST/api-keysCreate a key (session token required)
GET/api-keysList keys for your client
DELETE/api-keys/:idRevoke a key