api-keys

POST /v1/api-keys

Create an API key.

Барлық api-keys соңғы нүктелері

Аутентификация

API кілтін bearer токені ретінде жіберіңіз. Кілтте apikeys.manage рұқсаты болуы тиіс; онсыз кілтке 404 емес, 403 қатесі қайтарылады.

Ұйымыңыздың идентификаторы орналасатын жер

Бұл соңғы нүкте JSON корпусында өріс ретінде org_id қабылдайды.

Сіздің ұйым идентификаторыңыз басқару панеліндегі API кілттері экранында, кілттің өзінің жанында орналасқан. Бұл сіз жасайтын әрбір шақырудағы бірдей идентификатор.

Әрекет етіп көру

Бұрыштық жақшалардағы кез келген нәрсені өз мәндеріңізбен, ал кілт орналастырушысын басқару тақтасынан алынған кілтпен алмастырыңыз.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Жүйеге кіргенсіз бе? Бақылау тақтасындағы API консолі ұйымыңыздың нақты идентификаторы мен жеке кілтіңізді автоматты түрде толтырады да, нақты жауапты көре алуыңыз үшін сұрауды тікелей жұмыс істеп тұрған API арқылы орындайды. Бұл соңғы нүктені API консолінде ашыңыз

Мәліметтер

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Параметрлер

АтыTүріМіндеттіМазмұны
Idempotency-Key (header)stringЖоқClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Сұрау денесі

АтыTүріМіндеттіМазмұны
namestringИә
scopesstring[]ЖоқRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanЖоқMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullЖоқThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Жауап

АтыTүріМіндеттіМазмұны
idUuidИәUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringИә
prefixstringИәThe key's public lookup id (the middle segment of the token).
scopesstring[]ИәThe RBAC permission keys this key may exercise.
sandboxbooleanИәA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectЖоқWhen the key last authenticated a request; null if never used.
revoked_atobjectЖоқAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringИә
tokenstringИәThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Бұл соңғы нүкте қайтара алатын қателер

401 · 403 · 409 · 422 · 429