ADMIN_API_TOKEN for HFSAA-only administration. Keep this token in a password manager. HFSAA administrators can open /admin, enter the token once, and use the browser review console. The Worker replaces it with an eight-hour signed, secure browser session; the raw token is not stored in the session cookie.
When an applicant verifies their email, Resend notifies idris.ocasio@hfsaa.org, ahmed.qureshi@hfsaa.org, and imran.qasim@hfsaa.org that a request is ready for review. The message links to the admin portal; applicant details remain behind administrator authentication.
The JSON endpoints below remain available for trusted server-side operations.
Review pending applications
Approve an application
Test applications default to 10 requests per minute and 1,000 requests per month. The per-minute limit is fixed by the deployed environment for this MVP. Omitmonthly_limit to use the default, or assign an explicit monthly limit during review.
Inspect keys and usage
List active test keys with their current monthly request totals:Deny an application
Revoke a key
Developer self-service
Developers open/developer/manage and request a 15-minute sign-in link by email. The resulting secure session lasts eight hours and lets them:
- inspect key status, prefixes, monthly usage, and reset date;
- rotate a key, which immediately revokes the old key and emails a one-time replacement claim link;
- revoke a key permanently; and
- open the production-access application.