Skip to content
Getting started

Getting started

This guide takes you from a new Enzoguard account to a verified API key in less than 10 minutes. You will create an API key and verify it.

Before you begin

You need:

  • curl installed on your local machine.
  • A terminal where you can run shell commands.

This guide uses two different credentials:

  • A system key lets your backend manage apps and API keys, and call the verification API.
  • An API key identifies a client, service, or workload using your backend.

Treat both values as secrets. Enzoguard shows each plaintext key only once.

1. Sign up

Create an Enzoguard account, then log in.

2. Create a system key

Open System Key Management, enter a recognizable description such as getting-started, and select Create key.

Copy the key immediately, then save it in your current shell:

export EZ_SYSTEM_KEY='paste-your-system-key-here'

Do not commit the key to source control or include it in logs. For production, store it in your platform’s secret manager.

3. Create an app

An app represents a specific consumer of your backend product. It can represent an organization, a server, or any other client. Create an app named quickstart:

curl https://api.enzoguard.com/v1/realms/defaultrealm/apps \
  --header "Authorization: Bearer $EZ_SYSTEM_KEY" \
  --header 'Content-Type: application/json' \
  --data '{"name":"quickstart"}'

The response contains the new app’s ID and name. Enzoguard accepts either value in app management URLs, so the next command uses the name quickstart.

4. Create an API key

Create an API key for the app:

curl https://api.enzoguard.com/v1/realms/defaultrealm/apps/quickstart/api-keys \
  --header "Authorization: Bearer $EZ_SYSTEM_KEY" \
  --header 'Content-Type: application/json' \
  --data '{"description":"getting-started"}'

Copy the value of the key field from the response. This is the only time Enzoguard returns the complete API key. Save it in your current shell:

export API_KEY='paste-your-api-key-here'

5. Verify the API key

Your backend verifies an API key by sending the key and its realm ID to Enzoguard. The request itself is authenticated with your system key:

curl https://api.enzoguard.com/v1/verify-key \
  --header "Authorization: Bearer $EZ_SYSTEM_KEY" \
  --header 'Content-Type: application/json' \
  --data "{\"realm_id\":\"defaultrealm\",\"api_key\":\"$API_KEY\"}"

A successful verification returns "valid":true together with the app and realm identifiers. Your application can use that identity to decide what the caller is allowed to do.

You have now completed the full Enzoguard flow: create an app, issue an API key, and verify it.

Where to go next

  • Read Core concepts to learn how realms, apps, system keys, and API keys fit together.
  • Use the HTTP API reference for lifecycle operations such as listing, reading, and revoking API keys.