> ## Documentation Index
> Fetch the complete documentation index at: https://hfsaa.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Claim an approved API key once

> Generates the API key at confirmation time. The raw key is returned once and is never stored by HFSAA.



## OpenAPI

````yaml /openapi.yaml post /v1/developer/keys/claim
openapi: 3.1.0
info:
  title: HFSAA Public API
  version: 1.2.2
  description: >
    API-key protected access to HFSAA-certified restaurants, meat markets, and
    dining halls.

    Every directory-data route in the `/v1` namespace requires an API key; there
    are no

    anonymous data endpoints. Public health and developer-onboarding routes are
    explicitly

    marked with `security: []` and do not expose directory data.

    Developers can request test access without creating an account. Test keys do
    not

    expire automatically, but they are restricted to the test environment and
    quota.

    Successful data responses may be cached privately for no more than one hour.
  contact:
    name: HFSAA
servers:
  - url: https://api.hfsaa.org
    description: Production
  - url: https://hfsaa-public-api-staging.idris-ocasio.workers.dev
    description: Test
security:
  - ApiKeyAuth: []
paths:
  /v1/developer/keys/claim:
    post:
      tags:
        - Developer Access
      summary: Claim an approved API key once
      description: >-
        Generates the API key at confirmation time. The raw key is returned once
        and is never stored by HFSAA.
      operationId: claimDeveloperApiKey
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              required:
                - token
              properties:
                token:
                  type: string
      responses:
        '200':
          description: The newly generated API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/APIKeyClaim'
            text/html:
              schema:
                type: string
        '400':
          description: The claim token is invalid, expired, or already used.
      security: []
components:
  schemas:
    APIKeyClaim:
      type: object
      additionalProperties: false
      required:
        - api_key
        - environment
        - base_url
        - monthly_limit
      properties:
        api_key:
          type: string
          writeOnly: true
          description: Returned once. Store it securely.
        environment:
          type: string
          enum:
            - test
            - production
        base_url:
          type: string
          format: uri
          description: Base URL that accepts the issued key.
        monthly_limit:
          type: integer
          minimum: 1
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: hfsaa_test_... or hfsaa_live_...
      description: 'Use the API key as `Authorization: Bearer <api-key>`.'

````