A REST API for HYDROS aquarium controllers: look up devices, read live state and sensor history, and drive outputs and modes with overrides. One provider key for your integration, one device key per collective.
$ curl https://api.coralvuehydros.com/api/v1/device \ -H "Authorization: {provider_key}:{device_key}"
[{
"deviceId": "a0b765227294",
"friendlyName": "Display Tank Controller",
"type": "X4",
"owner": "user@example.com",
"shared": false
}]
Request one at coralvuehydros.com/api with a short description of your integration. Individuals wanting scripted or personal API access can request an unlisted provider key through the same form. Authentication uses the secret provider key value, not the Provider ID or provider key ID.
In the HYDROS app: open the device's Device Properties screen, tap Manage API Keys, then +. The owner picks your provider, a label, and a permission level (Read only or Read & write). Each key is scoped to that single device and can be revoked from the same screen at any time, which immediately cuts off access for anyone holding it.
Send both keys in the Authorization header as
{provider_key}:{device_key}, like the example above. The device
is resolved from the key, so no device identifier is needed. An HMAC-signed
header format is also available; both are documented in the
API reference.
Limits are enforced per device and per endpoint; all keys and sessions for the same device share its allowance. Device lookup and override reads allow 60 requests per minute; state, override writes, and metadata allow 10 per minute; polling sessions are limited to 5 per hour. Full table in the API reference.
Production is currently the only public environment; there is no sandbox. Controlled rate-limit testing is permitted against devices you are authorized to access.
For API questions or problems, visit support.coralvue.com. Include your provider key id (never the key itself) and an example request.
The HYDROS Developer API forum is the place to discuss integrations with other developers and the HYDROS team.
Treat both keys as secrets: keep them out of client-side code, repos, and support tickets.