18+ Only  |  Gambling can be addictive — please gamble responsibly  |  Gambling Help: 1800 858 858  |  GambleAware

API reference / Account

POST /v1/keys/resend

Email yourself a fresh API key

Rotate this account's key and mail the new one to its own verified address. Keys are sha256-hashed on insert and cannot be read back, /v1/keys/rotate needs the key you have lost, and the only regenerate UI is gated behind plan == "members" (the tips subscription), which no API customer holds. So there was no self-serve recovery at all: to 2026-08-25, 22 distinct IPs reached /account against 45 that minted a key. ⛔ ALWAYS 202, WHATEVER HAPPENS — unknown address, unverified account, rate-limited, mail failure. The response is byte-identical in every case. An endpoint that says "no such account" is an account-existence oracle for anyone with a list of emails, and this one names a mailbox that receives credentials. The key goes ONLY to the address already stored and verified on the row. Nothing the caller sends is used as a destination, so submitting someone else's address mails that person their own key and tells the requester nothing. Cost: 0 credits. Unauthenticated by necessity — the credential is the thing that is lost. ⚠️ KNOWN, ACCEPTED: response time is longer when the address does exist, because the send is awaited (see below). That leaks account existence to an attacker who can measure it. Accepted deliberately — the alternative is committing a rotation before knowing the mail went, which strands a real customer with a dead key. A timing signal on account existence is worth less than a customer's working credential, and the per-IP cap bounds sampling.

Requires X-API-Key

Request

curl -X POST 'https://api.puntersedge.online/v1/keys/resend' \
  -H 'X-API-Key: YOUR_KEY' \
  -H 'Content-Type: application/json' \
  -d '{"email": "you@example.com"}'

Parameters

NameIn TypeRequired Description
email body string yes

Responses

Status codes: 202, 401, 402, 422, 429, 500. Response bodies are JSON; the full schema is in /openapi.json.

Example response

202 application/json Field names and types are as the API returns them; values are a real sample, trimmed to a few items.

{
  "status": "accepted",
  "message": "If that address has a verified PuntersEdge API account, a new key is on its way to it. Your previous key keeps working for 24 hours, so anything running has time to roll over."
}

Related endpoints

Try it against live data

The free tier needs no credit card, and the sandbox endpoints need no key at all.

Get a free API key Quickstart
This site contains wagering-related analysis and is intended for Australian users aged 18+. Gambling involves risk. Please gamble responsibly.