api-keys

POST /v1/api-keys

Create an API key.

כל נקודות הקצה מסוג api-keys

אימות

שלחו מפתח API כאסימון נושא (bearer token). על המפתח לכלול את הרשאה apikeys.manage; מפתח שאינו כולל אותה יידחה בסטטוס 403, ולא 404.

המקום שבו מזהה הארגון שלך נכנס

נקודת קצה זו מקבלת את org_id כשדה בגוף ה-JSON.

מזהה הארגון שלך נמצא במסוף מפתחות ה-API בלוח הבקרה שלך, לצד המפתח עצמו. זהו אותו מזהה בכל קריאה שאתה מבצע.

נסה זאת

החלף כל דבר בסוגריים זוויתיים בערכים משלך, ואת מציין מיקום המפתח במפתח מלוח הבקרה שלך.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

מחובר? קונסולת ה-API בלוח הבקרה שלך מזינה את מזהה הארגון האמיתי שלך ואת המפתח שלך, ומריצה את הבקשה מול ה-API הפיזי כך שתוכל לראות את התגובה בפועל. פתח נקודת קצה זו במסוף ה-API

פרטים

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

פרמטרים

שםסוגנדרשמה זה
Idempotency-Key (header)stringלאClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

גוף הבקשה

שםסוגנדרשמה זה
namestringכן
scopesstring[]לאRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanלאMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullלאThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

תשובה

שםסוגנדרשמה זה
idUuidכןUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringכן
prefixstringכןThe key's public lookup id (the middle segment of the token).
scopesstring[]כןThe RBAC permission keys this key may exercise.
sandboxbooleanכןA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectלאWhen the key last authenticated a request; null if never used.
revoked_atobjectלאAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringכן
tokenstringכןThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

שגיאות שנקודה קצה זו עשויה להחזיר

401 · 403 · 409 · 422 · 429