Authentication & Scopes
All calls to the XeCubes API must be authenticated using an API key issued through your organization dashboard.
API Key Format​
XeCubes API keys are prefixed to indicate their environment:
- Live / Production:
xh_live_followed by 32 cryptographic alphanumeric characters (e.g.xh_live_9f8d7c6b5a4e3f2...). - Test / Sandbox:
xh_test_followed by 32 characters (e.g.xh_test_1a2b3c4d5e6f7g8...).
X-API-Key: xh_live_9f8d7c6b5a4e3f2...
Permission Scopes​
When creating an API key, assign only the minimal scopes required for your integration (principle of least privilege):
| Scope | Description | Associated Endpoints |
|---|---|---|
resume.parse | Upload single resume files for AI parsing & scoring | POST /recruiter/jobs/vendor/resume-analysis |
resume.parse.bulk | Async batch resume parsing pipelines | POST /recruiter/jobs/vendor/resume-analysis/bulk |
jobs.read | View organization jobs, stages, and criteria | GET /recruiter/jobs |
jobs.create | Create new job openings and criteria | POST /recruiter/jobs/create |
jobs.manage | Update or archive existing job configurations | PUT /recruiter/jobs/:id |
candidate.read | Access candidate interview transcripts & scorecards | GET /recruiter/candidates/:id |
webhook.manage | Subscribe, update, or inspect event webhooks | POST /recruiter/webhooks |
Query Available Scopes​
You can check which scopes your organization is authorized to grant by querying the services scope endpoint:
- cURL
- Node.js
- Python
curl -X GET "https://api.xecubes.com/recruiter/settings/services-api-scopes" \
-H "X-API-Key: xh_live_your_secret_key"
const res = await fetch('https://api.xecubes.com/recruiter/settings/services-api-scopes', {
headers: {
'X-API-Key': 'xh_live_your_secret_key'
}
});
const scopes = await res.json();
console.log('Granted scopes:', scopes);
import requests
response = requests.get(
"https://api.xecubes.com/recruiter/settings/services-api-scopes",
headers={"X-API-Key": "xh_live_your_secret_key"}
)
print(response.json())
Sample Response​
{
"status": "success",
"data": [
{
"scope": "resume.parse",
"description": "Ability to parse candidate resumes programmatically"
},
{
"scope": "resume.parse.bulk",
"description": "Ability to queue multiple resumes for bulk async processing"
},
{
"scope": "jobs.create",
"description": "Ability to create job configurations under organization"
},
{
"scope": "jobs.read",
"description": "Ability to list active or draft jobs"
}
]
}
Key Rotation Best Practices​
- Zero Downtime Rotation: Generate a new API key before revoking the old key. Update your environment variables and deploy the updated configuration.
- Monitoring Ingestion: Review key usage metrics in the XeCubes Dashboard to ensure traffic has shifted to the new key before deleting the retired credential.
- Emergency Revocation: If a key is accidentally committed or exposed in a client artifact, revoke it immediately from the Settings → API Keys portal. Revocation takes effect across all worldwide edge nodes in less than 3 seconds.