curl --request PATCH \
--url 'https://api.scanova.io/web-tracking/sites/7/api-keys/5/' \
--header 'Authorization: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{"is_active": false}'
{
"id": 5,
"name": "Server key",
"prefix": "aZ3kP9x1",
"is_active": true,
"created": "2026-09-01T10:06:00+05:30",
"modified": "2026-09-01T10:06:00+05:30"
}Web Tracking
Retrieve / update / delete an API key
GET, PATCH, DELETE /web-tracking/sites//api-keys//
GET
/
web-tracking
/
sites
/
{site_id}
/
api-keys
/
{pk}
/
curl --request PATCH \
--url 'https://api.scanova.io/web-tracking/sites/7/api-keys/5/' \
--header 'Authorization: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{"is_active": false}'
{
"id": 5,
"name": "Server key",
"prefix": "aZ3kP9x1",
"is_active": true,
"created": "2026-09-01T10:06:00+05:30",
"modified": "2026-09-01T10:06:00+05:30"
}Manages a single tracking-site API key. Use
PATCH with is_active: false to deactivate a key without deleting its record (e.g. to free up a slot under the 2-active-key limit while keeping history).
Requires the account’s
CONVERSION_TRACKING quota. The raw key value is never returned again after generation — only prefix is exposed here.integer
required
Tracking site ID.
integer
required
API key ID.
string
New label (PATCH).
boolean
Deactivate/reactivate the key (PATCH) — a deactivated key stops authenticating server-events requests.
curl --request PATCH \
--url 'https://api.scanova.io/web-tracking/sites/7/api-keys/5/' \
--header 'Authorization: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{"is_active": false}'
204 on delete, 404 if site_id/pk isn’t owned by this account.
Related
- List API keys
- Generate an API key
- Management API overview — the auth scheme and quota architecture this endpoint is part of.
Authorizations
Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: 401f7ac837da42b97f613d789819ff93537bee6a. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. api.scanova.io) — the same key sent to the regular API host will not authenticate.
Response
One API key (prefix only, never the raw key).
Was this page helpful?