Signing keys
A zone with token authentication on serves only links signed with its key. The key has an endpoint of its own, so that listing zones never returns a secret: one call reads it and one issues a new one.
Read the key
GET https://api.cachegenie.com/v1/cdn/{ZONE_ID}/token-key
curl https://api.cachegenie.com/v1/cdn/AB12CD34E/token-key \
-H "Authorization: Bearer YOUR_API_KEY"
{
"CODE": 200,
"MESSAGE": "Signing Key Returned.",
"DATA": {
"TOKEN_AUTH": 0,
"TOKEN_AUTH_KEY":
"b7e3f1a9c2d84e6f0a1b2c3d4e5f60718293a4b5c6d7e8f9a0b1c2d3e4f5a6b7"
}
}
- TOKEN_AUTH (Integer): 1 when the zone is refusing unsigned links, 0 when it is not. The key is returned either way, so you can sign your links and test them before switching it on.
- TOKEN_AUTH_KEY (String): the zone's signing key, 64 hexadecimal characters. Keep it on your server: anyone holding it can sign a link for anything in the zone.
A zone that somehow has no key is given one by this call, so the one failure it can answer is a write that did not go through: 500 Unable to issue a new signing key - Internal Server Error, please try again.
Issue a new key
POST https://api.cachegenie.com/v1/cdn/{ZONE_ID}/token-key
Replaces the key and returns the new one with MESSAGE New Signing Key Issued.. Every link signed with the old key stops working as soon as the locations pick the change up, within seconds, so this is for a key that has been exposed, or for a deliberate reset once your application is ready to sign with the new one. A write that did not go through is 500 Unable to issue a new signing key - Internal Server Error, please try again.
Switching signed links on
The switch is TOKEN_AUTH on the zone object, set through Zones. How a link is signed, in PHP, Node and Python, and how to sign a folder for HLS and DASH, is in Token authentication.