All API HubAll API Hub
Homepage
Getting Started
Frequently Asked Questions
Changelog
  • 简体中文
  • English
  • 日本語
Homepage
Getting Started
Frequently Asked Questions
Changelog
  • 简体中文
  • English
  • 日本語
  • 🚀 Getting Started

    • Getting Started
    • Permission Management (Optional Permissions)
    • Safari Extension Installation Guide
    • Installation Guide for QQ / 360 and Other Browsers
  • 🔑 Accounts & Credentials

    • Account Management
    • API Credentials
    • Key Management
    • Bookmark Management
    • Sorting Priority Settings
  • 📊 Analytics & Dashboard

    • Balance History
    • Usage Analysis
    • Share Snapshot
    • Model List and Price Comparison
    • Automatic Refresh and Real-time Data
  • 🤖 Automation Helpers

    • Automatic Check-in and Check-in Monitoring
    • Redemption Assist
    • Web AI API Sniffing and Verification
    • Cloudflare Shield Bypass Assistant
  • 🔌 Ecosystem & Integrations

    • Supported Site List
    • LDOH Site Lookup
    • Supported Export Tools List
    • Quick Export Site Configuration
    • CLIProxyAPI Integration and One-Click Import
  • 🛠️ Admin Management

    • Managed Site Model Sync
    • Self-Hosted Site Management
    • Model Redirect
    • New API Security Verification
  • 🛡️ Data & Support

    • Data Import and Export
    • WebDAV Backup and Automatic Synchronization
    • All API Hub Privacy Policy
    • Troubleshooting Guide for Auto-Identification
    • Developer & Advanced Tools
    • Frequently Asked Questions
  • Changelog

New API Security Verification

For site owners or administrators of systems based on the New API series (New API, DoneHub, Veloera, etc.). When you perform sensitive operations in the extension (e.g., viewing hidden channel keys, modifying critical settings, batch synchronization, etc.), you may need to complete a security verification.

Why is Verification Needed?

To ensure account security, New API systems usually audit administrator operations. If the following features are enabled in your backend, the extension will guide you through the corresponding verification process:

  1. Two-Factor Authentication (2FA/OTP): Requires a 6-digit verification code at login.
  2. Secure Verification: Requires identity re-confirmation when reading channel keys or making sensitive API calls.
  3. Passkey or Manual Login: In some environments where login sessions cannot be obtained automatically via the interface, you will be guided to the web interface to complete the login.

Common Verification Flows

1. Login Verification Code

When you first connect to a self-hosted site, or when your login status expires, the extension will pop up a verification window:

  • Please open your authenticator app (e.g., Google Authenticator, Bitwarden, etc.).
  • Enter the 6-digit verification code and submit.
  • Once verified, the extension will automatically save the login session, and subsequent operations will not prompt for verification during the validity period.

2. Secondary Verification for Sensitive Operations

In "Self-hosted Site Management", if you attempt to:

  • Click "Show Key" to view the real key of a channel.
  • Perform "Channel Migration" which requires extracting private information from the source site.

The extension will pop up a request for a secondary verification code. This is usually the same as your login verification code but has a shorter validity period.

3. Passkey or Manual Guidance

If your site is configured with Passkey (WebAuthn) or other verification methods that the extension cannot handle automatically:

  • The extension will display "Manual Verification Required".
  • Click "Go to Site to Complete Verification" and follow the instructions in the pop-up window.
  • Once completed, return to the extension and click "Verification Completed" to continue.

Common Issues

IssueSolution
Verification Code Error1. Check if your phone time is synchronized with the server.
2. Ensure you are entering the 2FA code for the correct site.
Verification Box Won't Pop UpEnsure your Admin Token and User ID are correctly configured and that you have sufficient administrative permissions.
Frequent Session ExpirationSome systems have very short session validity or have IP binding enabled. We recommend checking the backend security settings.
Can't Find 2FA SettingsPlease enable two-factor authentication on the "Personal Settings" page of your self-hosted site.

Related Documents

  • Self-hosted Site Management
  • Managed Site Model Synchronization
Last Updated: 5/3/26, 7:12 PM
Contributors: anime, github-actions[bot], qixing-jk
Prev
Model Redirect