api-keys

POST /v1/api-keys

Create an API key.

Lahat ng api-keys endpoint

Pagpapatotoo

Magpadala ng API key bilang isang bearer token. Kailangang taglayin ng key ang pahintulot na apikeys.manage; ang key na wala nito ay tatanggihan gamit ang 403, hindi 404.

Kung saan mapupunta ang id ng iyong organisasyon

Ang endpoint na ito ay kumukuha ng org_id bilang isang field sa JSON body.

Ang id ng iyong organisasyon ay nasa screen ng mga API key sa iyong dashboard, sa tabi mismo ng key. Ito ang parehong id sa bawat tawag na gagawin mo.

Subukan ito

Palitan ang anuman sa loob ng mga panaklong na may anggulo ng iyong sariling mga halaga, at ang placeholder ng key na may key mula sa iyong dashboard.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Nakalagda? Ang API console sa iyong dashboard ay awtomatikong naglalagay ng iyong tunay na ID ng organisasyon at sariling susi, at pinapatakbo ang kahilingan laban sa live na API upang makita mo ang aktwal na tugon. Buksan ang endpoint na ito sa console ng API

Mga Detalye

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Mga Parameter

PangalanUriKailanganAno ito
Idempotency-Key (header)stringHindiClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Katawan ng kahilingan

PangalanUriKailanganAno ito
namestringOo
scopesstring[]HindiRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanHindiMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullHindiThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Tugon

PangalanUriKailanganAno ito
idUuidOoUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringOo
prefixstringOoThe key's public lookup id (the middle segment of the token).
scopesstring[]OoThe RBAC permission keys this key may exercise.
sandboxbooleanOoA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectHindiWhen the key last authenticated a request; null if never used.
revoked_atobjectHindiAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringOo
tokenstringOoThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Mga error na maibabalik ng endpoint na ito

401 · 403 · 409 · 422 · 429