api-keys

POST /v1/api-keys

Create an API key.

Bütün api-keys nöqtələri

Doğrulama

API açarını bearer token kimi göndərin. Açar apikeys.manage icazəsinə malik olmalıdır; bu icazəsi olmayan açar 404 deyil, 403 xətası ilə rədd edilir.

Təşkilatınızın identifikatorunun yerləşdiyi yer

Bu son nöqtə JSON gövdəsində sahə kimi org_id qəbul edir.

Təşkilatınızın identifikatoru idarə panelinizdəki API açarları ekranında, açarın özünün yanında yerləşir. Bu, etdiyiniz hər bir sorğuda eyni identifikatordur.

Sınaqdan keçir

Bucaqlı mötərizələrdə olan hór şeyi öz qiymətlərinizlə, açar yertutucusunu isə idarə panelinizdən bir açarla əvəz edin.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Sistemə daxil olmusunuz? İdarə panelinizdəki API konsolu real təşkilatınızın identifikatorunu və öz açarınızı avtomatik doldurur, sorğunu canlı API-yə qarşı icra edir ki, siz faktiki cavabı görə biləsiniz. Bu son nöqtəni API konsolunda açın

Təfərrüatlar

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Parametrlər

AdTipTələb olunurNədir
Idempotency-Key (header)stringXeyrClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Sorğu gövdəsi

AdTipTələb olunurNədir
namestringBəli
scopesstring[]XeyrRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanXeyrMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullXeyrThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Cavab

AdTipTələb olunurNədir
idUuidBəliUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringBəli
prefixstringBəliThe key's public lookup id (the middle segment of the token).
scopesstring[]BəliThe RBAC permission keys this key may exercise.
sandboxbooleanBəliA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectXeyrWhen the key last authenticated a request; null if never used.
revoked_atobjectXeyrAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringBəli
tokenstringBəliThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Bu son nöqtənin qaytara biləcəyi xətalar

401 · 403 · 409 · 422 · 429