Create an API key

POST/o/{org}/api-keys
View .md

Mints a key that acts as the caller (an org admin) on the session routes. The secret is in this response only; it is never stored or shown again. Without expires_at the key never expires.

Authenticate with a signed-in session token (an API key cannot call this route).

Path parameters

orgstringrequired

The org's slug or id. A caller with no role in the org gets 404.

Request body

namestringrequired
at most 100 characters
scopesarray of stringoptional

Defaults to both scopes.

max_concurrentintegeroptional

Runs this key may have in progress at once.

Default 4min 1max 100
expires_atstring | nulloptional

In the future and at most one year away.

Format date-time

Responses

201The key, with its secret.
idstringrequired

key_…; use it in the key routes.

namestringrequired
prefixstringrequired

The secret's first characters, to tell keys apart.

scopesarray of stringrequired
max_concurrentintegerrequired
webhook_urlstring | nullrequired
expires_atstring | nullrequired
Format date-time
created_byobjectrequired
2 fields
idstringrequired
emailstring | nullrequired
last_used_atstring | nullrequired
Format date-time
created_atstringrequired
Format date-time
secretstringrequired

The key's secret. Only in the create and rotate responses; never shown again.

webhook_secretstringoptional

The webhook signing secret. Only in the update response that minted it.

400An invalid field (VALIDATION_ERROR).
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
401No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional
404No such resource for the caller, including one that exists in an org the caller cannot see.
errorstringoptional

A sentence for a person.

codestringoptional

Stable machine code, e.g. AUTH_FAILED, NOT_FOUND, VALIDATION_ERROR, RATE_LIMITED, PLAN_REQUIRED.

error_codestringoptional

The machine code on routes that name it this way.

messagestringoptional
requestIdstringoptional