Authentication
Kist has two credentials with different jobs: a short-lived session token for account actions, and a long-lived API key for programmatic proof operations.
Session tokens
Obtained by signing in or registering. They are short-lived (15 minutes) and used for account operations such as creating and listing API keys, and credit top-ups.
POST
/auth/registerCreate an account with email + password (12+ chars)POST
/auth/loginExchange credentials for a session tokenAPI keys
API keys (they look like kist_live_…) authorize metered proof operations. Send them as a Bearer token on every API request. Keys are hashed at rest and shown only once at creation.
# Every metered request carries your keyAuthorization: Bearer <KIST_API_KEY>
Treat keys like passwords
If a key leaks, revoke it in the console immediately. Revocation is instant.
Managing keys
POST
/api-keysCreate a key (session token required)GET
/api-keysList keys for your clientDELETE
/api-keys/:idRevoke a key