api-keys

POST /v1/api-keys

Create an API key.

جميع نقاط نهاية api-keys

المصادقة

أرسل مفتاح واجهة برمجة التطبيقات (API key) كرمز حامل (bearer token). يجب أن يحمل المفتاح إذن apikeys.manage؛ والمفتاح الذي لا يملكه يُرفض بالرمز 403 وليس 404.

حيث يتم إدخال معرف مؤسستك

تقبل هذه نقطة النهاية org_id حقلًا في نص JSON.

معرف مؤسستك موجود على شاشة مفاتيح واجهة برمجة التطبيقات (API) في لوحة تحكمك، بجوار المفتاح نفسه. وهو نفس المعرف في كل طلب تجريه.

جربه الآن

استبدل أي شيء بين أقواس زاوية بقيمك الخاصة، والعنصر النائب للمفتاح بمفتاح من لوحة تحكمك.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

هل سجلت الدخول؟ تقوم وحدة تحكم واجهة برمجة التطبيقات في لوحة التحكم الخاصة بك بربط معرف مؤسستك الحقيقي ومفتاحك الخاص، وتنفذ الطلب مقابل واجهة برمجة التطبيقات المباشرة لتتمكن من رؤية الاستجابة الفعلية. افتح هذه النهاية الطرفية في وحدة تحكم API

التفاصيل

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

المعلمات

الاسمالنوعمطلوبما هو هذا
Idempotency-Key (header)stringلاClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

جسم الطلب

الاسمالنوعمطلوبما هو هذا
namestringنعم
scopesstring[]لاRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanلاMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullلاThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

الاستجابة

الاسمالنوعمطلوبما هو هذا
idUuidنعمUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringنعم
prefixstringنعمThe key's public lookup id (the middle segment of the token).
scopesstring[]نعمThe RBAC permission keys this key may exercise.
sandboxbooleanنعمA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectلاWhen the key last authenticated a request; null if never used.
revoked_atobjectلاAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringنعم
tokenstringنعمThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

الأخطاء التي يمكن أن تُرجعها نقطة النهاية هذه

401 · 403 · 409 · 422 · 429