The API key object
What Trollflix returns about your API key, and how the key management endpoints authenticate.
These endpoints power Settings → Integrations. They are documented here so you know exactly what each button does and what it returns.
| Method | Path | Description |
|---|---|---|
POST | /user_settings/get_api_key | Retrieve your key's details |
POST | /user_settings/create_api_key | Create your key |
POST | /user_settings/rotate_api_key | Replace your key, revoking the old one |
POST | /user_settings/delete_api_key | Delete and revoke your key |
Signed-in session, not an API key
Unlike the rest of the API, these endpoints do not accept an API key. They use your signed-in Trollflix session, the same one the website and app use, and browsers only allow Trollflix's own websites to call them.
That is deliberate: if your key ever leaks, whoever holds it cannot rotate or delete it to lock you out, and cannot create keys of their own. Managing keys always requires you to be signed in to Trollflix.
In practice, manage your key from Settings → Integrations on the website or in the app.
Base URL
https://backend.trollflix.com/api/phpRequests are POST with a JSON body (Content-Type: application/json). None of
these endpoints take parameters, so the body is {}.
The API key object
Trollflix never returns your full key after it is created, because it only stores a hash of it. This object describes the key without revealing it.
{
"key_hint": "tfx_3f9a...c2b1",
"created_at_unix": 1790841600,
"rotated_at_unix": 1791446400,
"last_used_at_unix": 1791532800,
"uses_count": 42
}Prop
Type
Errors
| Code | Field | Meaning |
|---|---|---|
api_key_already_exists | error_message_code | You already have a key. Rotate it instead. |
api_key_not_found | error_message_code | You have no key to rotate or delete. |
user_authentication_failed | general_error | You are not signed in, or your session expired. Sign in again. |