Rotate this account's key and mail the new one to its own verified address. Keys are sha256-hashed on insert and cannot be read back, /v1/keys/rotate needs the key you have lost, and the only regenerate UI is gated behind plan == "members" (the tips subscription), which no API customer holds. So there was no self-serve recovery at all: to 2026-08-25, 22 distinct IPs reached /account against 45 that minted a key. ⛔ ALWAYS 202, WHATEVER HAPPENS — unknown address, unverified account, rate-limited, mail failure. The response is byte-identical in every case. An endpoint that says "no such account" is an account-existence oracle for anyone with a list of emails, and this one names a mailbox that receives credentials. The key goes ONLY to the address already stored and verified on the row. Nothing the caller sends is used as a destination, so submitting someone else's address mails that person their own key and tells the requester nothing. Cost: 0 credits. Unauthenticated by necessity — the credential is the thing that is lost. ⚠️ KNOWN, ACCEPTED: response time is longer when the address does exist, because the send is awaited (see below). That leaks account existence to an attacker who can measure it. Accepted deliberately — the alternative is committing a rotation before knowing the mail went, which strands a real customer with a dead key. A timing signal on account existence is worth less than a customer's working credential, and the per-IP cap bounds sampling.
X-API-Key
curl -X POST 'https://api.puntersedge.online/v1/keys/resend' \
-H 'X-API-Key: YOUR_KEY' \
-H 'Content-Type: application/json' \
-d '{"email": "you@example.com"}'
| Name | In | Type | Required | Description |
|---|---|---|---|---|
email |
body | string | yes |
Status codes: 202, 401, 402, 422, 429, 500. Response bodies are JSON; the full schema is in /openapi.json.
202 application/json
Field names and types are as the API returns them; values are a real sample, trimmed to a few items.
{
"status": "accepted",
"message": "If that address has a verified PuntersEdge API account, a new key is on its way to it. Your previous key keeps working for 24 hours, so anything running has time to roll over."
}
GET /v1/account — Your account: email, plan, password, billing and consent statusPOST /v1/account/marketing — Turn promotional emails on or off for your accountPOST /v1/account/password — Set or change your account passwordGET /v1/billing/overage — Overage: state, rate and ceilingPOST /v1/billing/overage — Switch overage on or offGET /v1/billing/portal — Self-service billing portal linkPOST /v1/billing/portal — Billing portal link (console; confirms your password)GET /v1/billing/upgrade-link — A signed link to your prorated upgrade pageThe free tier needs no credit card, and the sandbox endpoints need no key at all.
Get a free API key Quickstart