api-keys

POST /v1/api-keys

Create an API key.

همه نقاط پایانی api-keys

احراز هویت

یک کلید API را به عنوان یک توکن حامل ارسال کنید. این کلید باید دارای مجوز apikeys.manage باشد؛ کلیدی که فاقد آن باشد با خطای 403 رد می‌شود، نه 404.

جایی که شناسه سازمان شما قرار می‌گیرد

این نقطه پایانی org_id را به عنوان یک فیلد در بدنه JSON دریافت می‌کند.

شناسه سازمان شما در صفحه کلیدهای API در داشبوردتان، در کنار خود کلید قرار دارد. این شناسه در تمام درخواست‌هایی که ارسال می‌کنید یکسان است.

امتحان کنید

هر چیزی را که داخل براکت‌های زاویه‌دار قرار دارد با مقادیر خودتان جایگزین کنید، و نگهدارنده کلید را با کلیدی از داشبورد خود جایگزین نمایید.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

وارد شده‌اید؟ کنسول API در داشبورد شما شناسه سازمان واقعی و کلید خودتان را پر می‌کند و درخواست را روی API زنده اجرا می‌کند تا بتوانید پاسخ واقعی را ببینید. این نقطه پایانی را در کنسول API باز کنید

جزئیات

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

پارامترها

نامنوعالزامیچیست
Idempotency-Key (header)stringخیرClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

بدنه درخواست

نامنوعالزامیچیست
namestringبله
scopesstring[]خیرRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanخیرMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullخیرThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

پاسخ

نامنوعالزامیچیست
idUuidبلهUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringبله
prefixstringبلهThe key's public lookup id (the middle segment of the token).
scopesstring[]بلهThe RBAC permission keys this key may exercise.
sandboxbooleanبلهA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectخیرWhen the key last authenticated a request; null if never used.
revoked_atobjectخیرAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringبله
tokenstringبلهThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

خطاهایی که این نقطه پایانی می‌تواند برگرداند

401 · 403 · 409 · 422 · 429