api-keys

POST /v1/api-keys

Create an API key.

Όλα τα τελικά σημεία api-keys

Πισtoποίηση

Στείλτε ένα κλειδί API ως διακριτικό φορέα (bearer token). Το κλειδί πρέπει να διαθέτει το δικαίωμα apikeys.manage· ένα κλειδί που δεν το διαθέτει απορρίπτεται με 403, όχι 404.

Πού μπαίνει το αναγνωριστικό του οργανισμού σας

Αυτό το endpoint δέχεται το πεδίο org_id στο σώμα JSON.

Το αναγνωριστικό του οργανισμού σας βρίσκεται στην οθόνη των κλειδιών API στον πίνακα ελέγχου σας, δίπλα στο ίδιο το κλειδί. Είναι το ίδιο αναγνωριστικό σε κάθε κλήση που πραγματοποιείτε.

Δοκιμάστε το

Ατικatastήstε ό,τι βρίskεtai μέσα σe γώniaδeς μe τis δikές sas timές, kai to placeholder klεidioύ μe éna klεidi apó ton pinaka ελέgchou sas.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Συνδεθήκατε; Η κονσόλα API στον πίνακα ελέγχου σας συμπληρώνει το πραγματικό αναγνωριστικό του οργανισμού σας και το δικό σας κλειδί, και εκτελεί το αίτημα στο ζωντανό API, ώστε να μπορείτε να δείτε την πραγματική απόκριση. Ανοίξτε αυτό το τελικό σημείο στην κονσόλα API

Λεπτομέρειες

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Παράμετροι

ΌνομαΤύpοςΥποχρεωτικόΤι είναι
Idempotency-Key (header)stringΌχιClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Σώμα αίτησης

ΌνομαΤύpοςΥποχρεωτικόΤι είναι
namestringΝαι
scopesstring[]ΌχιRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanΌχιMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullΌχιThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Απάντηση

ΌνομαΤύpοςΥποχρεωτικόΤι είναι
idUuidΝαιUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringΝαι
prefixstringΝαιThe key's public lookup id (the middle segment of the token).
scopesstring[]ΝαιThe RBAC permission keys this key may exercise.
sandboxbooleanΝαιA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectΌχιWhen the key last authenticated a request; null if never used.
revoked_atobjectΌχιAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringΝαι
tokenstringΝαιThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Σφάλματα που μπορεί να επιστρέψει αυτό το τελικό σημείο

401 · 403 · 409 · 422 · 429