api-keys

POST /v1/api-keys

Create an API key.

Alle api-keys Endpunkte

Authentifizierung

Senden Sie einen API-Schlüssel als Bearer-Token. Der Schlüssel muss über die Berechtigung apikeys.manage verfügen; ein Schlüssel ohne diese wird mit 403 statt 404 abgelehnt.

Hier kommt Ihre Organisations-ID hin

Dieser Endpunkt akzeptiert org_id als Feld im JSON-Body.

Die ID Ihrer Organisation finden Sie im Dashboard auf dem Bildschirm für API-Schlüssel direkt neben dem Schlüssel selbst. Sie ist bei jedem Ihrer Aufrufe dieselbe.

Ausprobieren

Ersetzen Sie alles in spitzen Klammern durch Ihre eigenen Werte und den Platzhalter für den Schlüssel durch einen Schlüssel aus Ihrem Dashboard.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Angemeldet? Die API-Konsole in Ihrem Dashboard trägt automatisch Ihre echte Organisations-ID sowie Ihren eigenen Schlüssel ein und führt die Anfrage gegen die Live-API aus, sodass Sie die tatsächliche Antwort sehen können. Öffnen Sie diesen Endpunkt in der API-Konsole

Details

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Parameter

NameTypErforderlichWas es ist
Idempotency-Key (header)stringNeinClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Anfragekörper

NameTypErforderlichWas es ist
namestringJa
scopesstring[]NeinRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanNeinMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullNeinThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Antwort

NameTypErforderlichWas es ist
idUuidJaUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringJa
prefixstringJaThe key's public lookup id (the middle segment of the token).
scopesstring[]JaThe RBAC permission keys this key may exercise.
sandboxbooleanJaA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectNeinWhen the key last authenticated a request; null if never used.
revoked_atobjectNeinAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringJa
tokenstringJaThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Fehler, die dieser Endpunkt zurückgeben kann

401 · 403 · 409 · 422 · 429