api-keys

POST /v1/api-keys

Create an API key.

ყველა api-keys ენდპოინტი

ავტორიზაცია

API გასაღები გაგზავნეთ როგორც მატარებელი ტოკენი (bearer token). გასაღებს უნდა ჰქონდეს apikeys.manage ნებართვა; ამის გარეშე გასაღები უარყოფილი იქნება 403 და არა 404 სტატუსით.

სwhere your organisation id goes-ის ადგილი

ესენდპოინტი იღებს org_id-ს JSON ტანის ველად.

თქვენი ორგანიზაციის ID მითითებულია თქვენი სამართავი პანელის API გასაღებების ეკრანზე, თავად გასაღებთან ახლოს. ის ერთნაირია თქვენ მიერ განხორციელებულ ყველა გამოძახებაში.

სცადეთ

შეSubstituted any value inside angle brackets with your own and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

შესული ხართ? თქვენი სამართავ პანელში არსებული API კონსოლი ავტომატურად ამატებს თქვენი რეალური ორგანიზაციის ID-სა და საკუთარ გასაღებს და ატარებს მოთხოვნას ცოცხალ API-ს წინააღმდეგ, რათა იხილოთ რეალური პასუხი. გაAღით ეს ენდპოინტი API კონსოლში

დეტალები

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

პარამეტრები

სახელიტიპისავალდებულორა არის ეს
Idempotency-Key (header)stringარაClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

მოთხოვნის სხეული

სახელიტიპისავალდებულორა არის ეს
namestringდიახ
scopesstring[]არაRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanარაMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullარაThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

პასუხი

სახელიტიპისავალდებულორა არის ეს
idUuidდიახUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringდიახ
prefixstringდიახThe key's public lookup id (the middle segment of the token).
scopesstring[]დიახThe RBAC permission keys this key may exercise.
sandboxbooleanდიახA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectარაWhen the key last authenticated a request; null if never used.
revoked_atobjectარაAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringდიახ
tokenstringდიახThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

შეცდომები, რომლებიც ამ ენდპოინტს შეუძლია დააბრუნოს

401 · 403 · 409 · 422 · 429