Skip to main content

Authentication & Scopes

All calls to the XeCubes API must be authenticated using an API key issued through your organization dashboard.


API Key Format​

XeCubes API keys are prefixed to indicate their environment:

  • Live / Production: xh_live_ followed by 32 cryptographic alphanumeric characters (e.g. xh_live_9f8d7c6b5a4e3f2...).
  • Test / Sandbox: xh_test_ followed by 32 characters (e.g. xh_test_1a2b3c4d5e6f7g8...).
X-API-Key: xh_live_9f8d7c6b5a4e3f2...

Permission Scopes​

When creating an API key, assign only the minimal scopes required for your integration (principle of least privilege):

ScopeDescriptionAssociated Endpoints
resume.parseUpload single resume files for AI parsing & scoringPOST /recruiter/jobs/vendor/resume-analysis
resume.parse.bulkAsync batch resume parsing pipelinesPOST /recruiter/jobs/vendor/resume-analysis/bulk
jobs.readView organization jobs, stages, and criteriaGET /recruiter/jobs
jobs.createCreate new job openings and criteriaPOST /recruiter/jobs/create
jobs.manageUpdate or archive existing job configurationsPUT /recruiter/jobs/:id
candidate.readAccess candidate interview transcripts & scorecardsGET /recruiter/candidates/:id
webhook.manageSubscribe, update, or inspect event webhooksPOST /recruiter/webhooks

Query Available Scopes​

You can check which scopes your organization is authorized to grant by querying the services scope endpoint:

curl -X GET "https://api.xecubes.com/recruiter/settings/services-api-scopes" \
-H "X-API-Key: xh_live_your_secret_key"

Sample Response​

{
"status": "success",
"data": [
{
"scope": "resume.parse",
"description": "Ability to parse candidate resumes programmatically"
},
{
"scope": "resume.parse.bulk",
"description": "Ability to queue multiple resumes for bulk async processing"
},
{
"scope": "jobs.create",
"description": "Ability to create job configurations under organization"
},
{
"scope": "jobs.read",
"description": "Ability to list active or draft jobs"
}
]
}

Key Rotation Best Practices​

  1. Zero Downtime Rotation: Generate a new API key before revoking the old key. Update your environment variables and deploy the updated configuration.
  2. Monitoring Ingestion: Review key usage metrics in the XeCubes Dashboard to ensure traffic has shifted to the new key before deleting the retired credential.
  3. Emergency Revocation: If a key is accidentally committed or exposed in a client artifact, revoke it immediately from the Settings → API Keys portal. Revocation takes effect across all worldwide edge nodes in less than 3 seconds.