Mints a key that acts as the caller (an org admin) on the session
routes. The secret is in this response only; it is never stored or
shown again. Without expires_at the key never expires.
Authenticate with a signed-in session token (an API key cannot call this route).
Path parameters
The org's slug or id. A caller with no role in the org gets 404.
Request body
Defaults to both scopes.
Runs this key may have in progress at once.
4min 1max 100In the future and at most one year away.
Responses
201The key, with its secret.
key_…; use it in the key routes.
The secret's first characters, to tell keys apart.
2 fields
The key's secret. Only in the create and rotate responses; never shown again.
The webhook signing secret. Only in the update response that minted it.
400An invalid field (VALIDATION_ERROR).
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.
401No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.
404No such resource for the caller, including one that exists in an org the caller cannot see.
A sentence for a person.
Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.
The machine code on routes that name it this way.