Seerr-compatible API key (admin)
HTTP routes and behavior for seerr-compatible api key (admin).
GET /api/admin/seerr-api # { configured, api_key, issued_by, created_at }POST /api/admin/seerr-api # issue a key (replaces any earlier one at once); same shapeDELETE /api/admin/seerr-api # revoke; { configured: false }The one credential Cantinarr issues rather than holds for another service: the X-Api-Key that apps built against the Seerr API (Maintainerr, Dashbrr, Homepage and their kin) present under /api/v1 (see Seerr-compatible API). Because it exists to be pasted into another app, GET returns it to administrators, the way Radarr and Seerr show theirs; the compat surface itself never echoes it. One key per server, stored as the encrypted seerr_api_key row in settings (JSON: the key, the issuing admin’s user id, the issue time) and compared in constant time. The key acts as the administrator who issued it, so it stops working the moment that account is deleted or demoted, and reissuing invalidates the old value on the next call. Requires instances:manage.