Signing keys
A zone with token authentication on serves only links signed with its key. The key has an endpoint of its own, so that listing zones never returns a secret: one call reads it and one issues a new one.
Read the key#
https://api.cachegenie.com/v1/cdn/{ZONE_ID}/token-keycurl https://api.cachegenie.com/v1/cdn/AB12CD34E/token-key \
-H "Authorization: Bearer YOUR_API_KEY"{
"CODE": 200,
"MESSAGE": "Signing Key Returned.",
"DATA": {
"TOKEN_AUTH": 0,
"TOKEN_AUTH_KEY":
"b7e3f1a9c2d84e6f0a1b2c3d4e5f60718293a4b5c6d7e8f9a0b1c2d3e4f5a6b7"
}
}TOKEN_AUTHInteger1 when the zone is refusing unsigned links, 0 when it is not. The key is returned either way, so you can sign your links and test them before switching it on.TOKEN_AUTH_KEYStringthe zone's signing key, 64 hexadecimal characters. Keep it on your server: anyone holding it can sign a link for anything in the zone.
A zone that somehow has no key is given one by this call, so the one failure it can answer is a write that did not go through: 500 Unable to issue a new signing key - Internal Server Error, please try again.
Issue a new key#
https://api.cachegenie.com/v1/cdn/{ZONE_ID}/token-keyReplaces the key and returns the new one with MESSAGE New Signing Key Issued.. Every link signed with the old key stops working as soon as the locations pick the change up, within seconds, so this is for a key that has been exposed, or for a deliberate reset once your application is ready to sign with the new one. A write that did not go through is 500 Unable to issue a new signing key - Internal Server Error, please try again.
Switching signed links on#
The switch is TOKEN_AUTH on the zone object, set through Zones. How a link is signed, in PHP, Node and Python, and how to sign a folder for HLS and DASH, is in Token authentication.