api-keys

POST /v1/api-keys

Create an API key.

Semua titik akhir api-keys

Autentikasi

Kirim kunci API sebagai token bearer. Kunci tersebut harus memiliki izin apikeys.manage; kunci tanpa izin tersebut akan ditolak dengan status 403, bukan 404.

Tempat ID organisasi Anda dimasukkan

Titik akhir ini memerlukan org_id sebagai field dalam bodi JSON.

ID organisasi Anda berada di layar kunci API di dasbor Anda, di sebelah kunci itu sendiri. Itu adalah ID yang sama dalam setiap panggilan yang Anda buat.

Coba

Ganti apa pun di dalam tanda kurung sudut dengan nilai Anda sendiri, dan placeholder kunci dengan kunci dari dasbor Anda.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Sudah masuk? Konsol API di dasbor Anda akan mengisi ID organisasi asli dan kunci Anda sendiri, serta menjalankan permintaan terhadap API langsung sehingga Anda dapat melihat respons aktualnya. Buka titik akhir ini di konsol API

Detail

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Parameter

NamaJenisWajibTentang apa ini
Idempotency-Key (header)stringTidakClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Isi permintaan

NamaJenisWajibTentang apa ini
namestringYa
scopesstring[]TidakRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanTidakMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullTidakThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Tanggapan

NamaJenisWajibTentang apa ini
idUuidYaUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringYa
prefixstringYaThe key's public lookup id (the middle segment of the token).
scopesstring[]YaThe RBAC permission keys this key may exercise.
sandboxbooleanYaA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectTidakWhen the key last authenticated a request; null if never used.
revoked_atobjectTidakAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringYa
tokenstringYaThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Kesalahan yang dapat dikembalikan oleh titik akhir ini

401 · 403 · 409 · 422 · 429