API docs

GPTKeys REST API reference

Admin
Overview

Base URL: https://api.gptkeys.eu

Admin routes: Authorization: Bearer <GPTKEYS_ADMIN_TOKEN> or X-Admin-Token. CORS is open for all origins.

Key types (Mix vs Plus)

Every key has a key_type that controls which ChatGPT plans it can redeem from the cookie pool. Set at generation; all keys in a batch share the same type. Existing keys without a type are treated as mix.

Mix key

key_type: "mix" (default). Redeems any paid plan with no exceptions — including Plus, plus Go, Pro, Team, Enterprise, Business, Prolite, etc.

Plus key

key_type: "plus". Redeems Plus cookies only. No other plan is delivered. If Plus stock is empty, redeem fails with no valid Plus cookies available.

  • On redeem, the live checker confirms plan, then filters by key_type.
  • The assigned cookie sticks to the key; re-redeem reuses it if still valid and still matches the key type, otherwise pulls a new matching cookie from the pool.
  • Wrong-plan cookies are left in the pool for the other key type (a non-Plus cookie is not invalidated when a Plus key skips it).
Key generation

Every generate call creates a batch tied to a unique gen_order_id (e.g. genorder-a1b2c3). All keys in that batch share the same gen order, key_type, and optional group label.

  • Key format: GPTK- + 16 uppercase hex characters (e.g. GPTK-911362C45C7BEE6D)
  • count — how many keys to create (1–1000)
  • key_type — mix (default) or plus
  • group — optional string label (customer name, product tier, etc.)
  • On creation, each key log starts with: This key is generated by genorder-… at YYYY-MM-DD HH:MM:SS GMT
  • Then: Key type: mix or Key type: plus
  • If a group was set: Key group: …

Example — Mix keys

curl -sS -X POST https://api.gptkeys.eu/api/admin/keys/generate \
  -H "Authorization: Bearer $GPTKEYS_ADMIN_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"count":10,"key_type":"mix","group":"july-mix"}'

Example — Plus keys

curl -sS -X POST https://api.gptkeys.eu/api/admin/keys/generate \
  -H "Authorization: Bearer $GPTKEYS_ADMIN_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"count":5,"key_type":"plus","group":"july-plus"}'
Key logging

GET /api/admin/keys returns a log string array per key — a human-readable audit trail built from generation metadata and every redeem event.

Log line types

  • This key is generated by genorder-abc123 at 2026-07-30 09:00:00 GMT

    Always present — set at key creation from gen_order_id + created_at

  • Key type: plus

    Always present — mix or plus from generation

  • Key group: july-batch

    Present when group was set during generation

  • someuser (a1b2c3d4-e5f6-7890-…) redeemed GPTK-911362C45C7BEE6D at 2026-07-30 10:15:00 GMT
      from IP: 203.0.113.42

    Appended on every successful redeem. User name and id come from the EliteKeys auth API. Re-redeems (same or new device) each add a new line.

  • Devices seen: 2

    Shown once the key has been used — count of distinct device ids seen

  • This key was revoked at 2026-07-30 11:00:00 GMT

    Added when key is revoked via admin API

Key record fields

{
  "key": "GPTK-911362C45C7BEE6D",
  "status": "used",              // unused | used | revoked
  "key_type": "plus",            // mix | plus
  "group": "july-batch",
  "gen_order_id": "genorder-abc123",
  "created_at": "2026-07-30 09:00:00 GMT",
  "used_at": "2026-07-30 10:15:00 GMT",
  "revoked_at": "",
  "client_ip": "203.0.113.42",   // last redeem IP
  "elitekeys_user_id": "uuid",   // bound EliteKeys account
  "elitekeys_username": "someuser",
  "log": [ "…", "…" ]
}

Fetch keys from a batch with full log

curl -sS "https://api.gptkeys.eu/api/admin/keys?gen_order_id=genorder-abc123&status=all" \
  -H "Authorization: Bearer $GPTKEYS_ADMIN_TOKEN"

Redeem events are stored in key_redeem_events (elitekeys_user_id, elitekeys_username, client_ip, device_id, redeemed_at) and surfaced through log[]. Deleting a key removes its event history.

Keys — endpoints
POST/api/admin/keys/generateauth

Generate a batch of license keys.

Body

{ "count": 5, "key_type": "mix|plus", "group": "optional-batch-label" }

Response

{
  "ok": true,
  "keys": ["GPTK-…", "GPTK-…"],
  "gen_order_id": "genorder-abc123",
  "group": "optional-batch-label",
  "key_type": "mix"
}

count: 1–1000 (default 1). key_type: mix (default, all paid plans including Plus) or plus (Plus cookies only). group is optional. Each call creates a new gen_order_id. Keys are 16 hex chars prefixed with GPTK-.

GET/api/admin/keys/genordersauth

List generation batches (gen orders) with usage counts.

Query

?limit=200  (max 500, default 100)

Response

{
  "ok": true,
  "orders": [
    {
      "gen_order_id": "genorder-abc123",
      "group": "batch-label",
      "key_type": "mix",
      "created_at": "2026-07-30 09:00:00 GMT",
      "total": 10,
      "unused": 7,
      "used": 2,
      "revoked": 1
    }
  ]
}

Each order includes key_type (mix|plus). Use gen_order_id to filter keys, or bulk revoke/unrevoke/delete an entire batch.

GET/api/admin/keysauth

Paginated key log — each key includes a human-readable log[] trail.

Query

?page=1
&page_size=25        (max 100)
&status=all|unused|used|revoked
&gen_order_id=genorder-…
&q=…               (key, group, gen_order_id, key_type, elitekeys username/id)

Response

{
  "ok": true,
  "keys": [ { "key", "status", "group", "gen_order_id", "key_type", "created_at", "used_at", "revoked_at", "client_ip", "elitekeys_user_id", "elitekeys_username", "log": ["…"] } ],
  "total", "page", "page_size", "total_pages"
}
POST/api/admin/keys/revokeauth

Revoke keys — adds a revoke line to each key's log.

Body

{ "keys": ["GPTK-…"] }
// or { "gen_order_id": "genorder-…" }

Response

{ "ok": true, "updated": 3 }
POST/api/admin/keys/unrevokeauth

Restore revoked keys.

Body

Same body as revoke.

Response

{ "ok": true, "updated": 3 }
POST/api/admin/keys/deleteauth

Permanently delete keys (and their redeem event history).

Body

Same body as revoke.

Response

{ "ok": true, "deleted": 3 }
Public
GET/health

Service health check.

Response

{ "status": "ok", "service": "GPTKeys" }
GET/

API index — lists endpoint paths.

POST/api/elitekeys/login

Proxy EliteKeys credential verify (required before redeem).

Body

{ "username": "…", "password": "…" }

Response

{ "ok": true, "user": { "id", "email", "username" }, "session": { "access_token", "expires_at" }, "roles"? }

Server calls EliteKeys POST /api/public/rpc/verify (x-api-key), then issues a GPTKeys session token for redeem.

POST/api/redeem

Redeem a key for ChatGPT cookies (EliteKeys Bearer token required).

Body

{ "key": "GPTK-…", "device_id": "…" }

Authorization: Bearer <elitekeys access_token>. Plan pool depends on key_type: mix → any paid plan including Plus; plus → Plus only (errors if Plus stock empty). Cookie sticks to the key on re-redeem. Key binds to first EliteKeys account; concurrent multi-device use is flagged in admin abuse.

GET/extension/download

Download Chrome extension zip.

Other admin
GET/api/admin/statsauth

Key and cookie pool statistics, including per-plan breakdown.

Response

{
  "ok": true,
  "keys": { "total", "unused", "used", "revoked" },
  "cookies": { "total", "fresh", "reused", "invalid" },
  "plans": { "Plus": 21, "Go": 50 },
  "plan_detail": [ { "plan", "fresh", "used", "total" } ]
}

plans / plan_detail count valid cookies by ChatGPT plan (Plus, Go, Pro, …). Mix keys draw from non-Plus plans; Plus keys from Plus only.

GET/api/admin/abuseauth

List abuse alerts (concurrent lease/burst, key share, unusual traffic).

Query

?status=open|all
&page=1
&page_size=25        (max 100)

Response

{ "ok": true, "alerts": [ { "id", "type", "status", "elitekeys_user_id", "key_text", "detail", … } ], "total", "page", "page_size", "total_pages" }
POST/api/admin/abuse/banauth

Ban EliteKeys user from alert and revoke the involved key.

Body

{ "alert_id": 1 }
POST/api/admin/abuse/keepauth

Dismiss an abuse alert without banning.

Body

{ "alert_id": 1 }
GET/api/admin/abuse/statsauth

Abuse charts data: redeems over time, per gen order, top keys, open counts.

Query

?range=24h|7d
POST/api/admin/restockauth

Upload cookie export (.txt or .zip).

Body

multipart/form-data: file, optional validate=true
POST/api/admin/restock/stream?validate=trueauth

Restock with SSE progress.

Events: phase start|checking|progress|result|done|summary|error

POST/api/admin/recheck/streamauth

Live-recheck entire cookie library (SSE).

GPTKeys

This site is closed

GPTKeys is unavailable due to a personal matter. There is no ETA for reopening. Thank you for your understanding.

Access and redeem are disabled.