A phone signed in with an older version of the app holds the account's master key. The first time the updated app opens, it calls this endpoint once and moves to a key of its own.
01 · The call
POST https://opensolr.com/app/api/device_keyOnly while the phone has no key of its own yet; never again after it got one.
A JSON body with the account email and the api_key the phone holds, client_id opensolr-photos, and the phone's device_id, device_label and app_version.
02 · The answer
{"status": true, "msg": {"api_key": "…", "key_kind": "device"}}
- The app keeps the new key, encrypted, and uses it for every call from then on.
- The phone's row in Account › Devices turns from Account key to Own key.
- If the key it sends is refused, the app returns to its sign-in screen. If the server offers no key, the app carries on with the one it has and tries again at the next start.