All products
Developer security

Hexa API Guard

API Guard provides scoped Hexa Shield API keys for automation while API traffic can be protected by WAF, rate-limit, and IP policy at the reverse proxy.

Signature capability
Scoped API keys

This capability is backed by the Hexa Shield control plane and reverse-proxy architecture described in the project documentation.

One-time secret display with hashed storage

domains:read and domains:write scopes

analytics:read and events:read scopes

Revocation and last-used timestamps

Customer entitlement validation for API-key access

How it works

Protection in a clear request flow.

Each product is managed from the same Hexa Shield account and domain model instead of requiring separate control panels.

  1. 1

    Create a scoped API key

  2. 2

    Store the secret in your own secret manager

  3. 3

    Call supported Hexa Shield API endpoints

  4. 4

    Scopes are checked server-side

  5. 5

    Revoke the credential from the dashboard when no longer needed