Skip to main content
The MVP uses a Cloudflare Worker secret named ADMIN_API_TOKEN for HFSAA-only administration. Keep this token in a password manager. HFSAA administrators can open /admin, enter the token once, and use the browser review console. The Worker replaces it with an eight-hour signed, secure browser session; the raw token is not stored in the session cookie. When an applicant verifies their email, Resend notifies idris.ocasio@hfsaa.org, ahmed.qureshi@hfsaa.org, and imran.qasim@hfsaa.org that a request is ready for review. The message links to the admin portal; applicant details remain behind administrator authentication. The JSON endpoints below remain available for trusted server-side operations.

Review pending applications

Approve an application

Test applications default to 10 requests per minute and 1,000 requests per month. The per-minute limit is fixed by the deployed environment for this MVP. Omit monthly_limit to use the default, or assign an explicit monthly limit during review.
Approval emails a short-lived, one-time claim link. The API key itself does not expire automatically.

Inspect keys and usage

List active test keys with their current monthly request totals:
Use the returned key ID to inspect up to 90 days of per-endpoint daily usage plus the last 12 monthly totals:

Deny an application

Revoke a key

Revocation takes effect on the next API request and sends the owner a notification email. The database stores only the key’s SHA-256 hash and display-safe hint.

Developer self-service

Developers open /developer/manage and request a 15-minute sign-in link by email. The resulting secure session lasts eight hours and lets them:
  • inspect key status, prefixes, monthly usage, and reset date;
  • rotate a key, which immediately revokes the old key and emails a one-time replacement claim link;
  • revoke a key permanently; and
  • open the production-access application.
The portal never displays an existing raw key because HFSAA does not store it.