Account & keys
These endpoints accept an API key or a dashboard session token (X-Session-Token).
GET /v1/account
{ "success": true, "email": "you@example.com", "name": null, "company": null,
"plan": "pro", "subscription_status": "active", "period_end": null,
"active_keys": 1, "active_webhooks": 0 }
subscription_status is active, past_due (data access continues for a 3-day grace period) or canceled. period_end is the end of the current billing period.
PATCH /v1/account
Update the display name and/or company. Only the fields you send change. Each value is trimmed and capped at 120 characters, and an empty string clears it.
curl -X PATCH -H "X-API-Key: pk_live_xxx" -H "Content-Type: application/json" \
-d '{"name": "Ayesha Khan", "company": "Acme Fintech"}' \
"https://api.pakdatahub.com/v1/account"
GET /v1/keys
{ "success": true, "count": 1, "data": [
{ "id": "6fc4d775-87b8-4bfa-a1c7-5c1f84bab1b0", "key_prefix": "pk_live_AbCdEfGh…",
"label": "production", "created_at": "2026-09-24T13:55:41Z",
"revoked_at": null, "last_used_at": "2026-09-24T13:55:55Z" } ] }
last_used_at is updated at most once a minute.
POST /v1/keys
Create a key. Body: { "label": "staging" }, where label is optional. You can have at most 3 active keys; a fourth returns 403.
{ "success": true, "api_key": "pk_live_…", "key_prefix": "pk_live_AbCdEfGh…",
"note": "store this key now — it is shown only once" }
The plaintext api_key is returned once and never again.
DELETE /v1/keys/{id}
Revoke a key immediately. Requests using it then return 401.