API Guard provides scoped Hexa Shield API keys for automation while API traffic can be protected by WAF, rate-limit, and IP policy at the reverse proxy.
This capability is backed by the Hexa Shield control plane and reverse-proxy architecture described in the project documentation.
One-time secret display with hashed storage
domains:read and domains:write scopes
analytics:read and events:read scopes
Revocation and last-used timestamps
Customer entitlement validation for API-key access
Each product is managed from the same Hexa Shield account and domain model instead of requiring separate control panels.
Create a scoped API key
Store the secret in your own secret manager
Call supported Hexa Shield API endpoints
Scopes are checked server-side
Revoke the credential from the dashboard when no longer needed