This list is what makes an outside API call legitimate: a request to
/api must send a key from it in the x-api-key
header, and anything else is rejected. These keys are for callers outside
the application — this screen is inside it and needs none. The key is stored
as a SHA-256 digest and can never be read back; only its last four characters
are kept, to tell one key from another, so copy it before you leave this page.
| Client | Key | Added | Last used |
|---|
| BIN | Scheme | Brand | Type | Category | Country | Bank |
|---|