Centercode Release Notes
Back to all updates

Weekly Patch - October 4, 2026

by Ian Nicholson
New Features

Integrations

Your API key can now tell you which projects it reaches

What's new: Every external API call needs a project key in the URL, but until now there was no way to ask the API which projects a key could actually use. Integrators had to collect each project key by hand and register it on their side every time a new project came along. Now one call returns the whole list. No more copying keys around!

See it in action:

  1. Grab an API key you already use for an integration. It needs at least one project-level resource attached, like a feedback type, report, listener, or release type.
  2. Make a GET request to /v1/projects on the same external API address you already use, passing your key the usual way (?apiKey=<your key>).
  3. You'll get back a projects list, with each project's key (the same identifier used in other API paths), its name, and its status.
  4. Attach a resource from a brand-new project to that key and call /v1/projects again. The new project shows up on its own, with nothing to register on the integration's side. 🎉

Good to know:

  • You only see what the key can reach. The list includes only projects where the key has a resource attached. It never shows other projects or other communities.
  • Closed projects are included. Every project the key reaches is listed, and each one carries a status (such as Active, Closed, or Pending). Integrations should check that field rather than assume every listed project is open.
  • Projects without a project key are left out. If an attached project has no project key set, it won't appear in the list. To spot these, open the key's resources list in your community's API keys admin, where those projects are now labeled (no project key) next to their name. Add a project key and the project starts appearing in the list.
  • Keys with only community-level resources get an empty list. That's expected, not an error.
  • Authentication works the same as before. The call uses the same API key parameter and the same IP allowlist as every other external API endpoint. An invalid key, a missing key, or a call from an IP that isn't allowlisted is rejected the same way.