api-keys

POST /v1/api-keys

Create an API key.

सबै api-keys इन्डपइन्टहरू

प्रमाणीकरण

एपिआई कुञ्जीलाई बियरर टोकन (bearer token) को रूपमा पठाउनुहोस्। कुञ्जीसँग apikeys.manage अनुमति हुनुपर्छ; अनुमति नभएको कुञ्जीलाई 404 होइन, 403 मार्फत अस्वीकार गरिन्छ।

तपाईंको संस्थाको आइडी राख्ने ठाउँ

यो इन्डपोटले JSON बडीमा एक फिल्डको रूपमा org_id लिन्छ।

तपाईंको संस्थाको आइडी (ID) तपाईंको ड्यासबोर्डमा रहेको API कुञ्जीहरू (keys) स्क्रिनमा, कुञ्जीको छेउमा हुन्छ। तपाईंले गर्ने प्रत्येक कलमा यही आइडी प्रयोग हुन्छ।

प्रयास गर्नुहोस्

कोणीय कोष्ठकभित्र भएका जुनसुकै कुरालाई आफ्नो मानहरूद्वारा बदल्नुहोस्, र मुख्य स्थानहोल्डरलाई तपाईंको ड्यासबोर्डको कुञ्जीद्वारा बदल्नुहोस्।

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

लगइन गर्नुभएको छ? तपाईंको ड्यासबोर्डमा रहेको API कन्सोलले तपाईंको वास्तविक संस्थाको आईडी र आफ्नै कुञ्जी भरिदिन्छ, र लाइभ API विरुद्ध अनुरोध चलाउँछ ताकि तपाईंले वास्तविक प्रतिक्रिया हेर्न सक्नुहोस्। यो एन्डपोइन्टलाई API कन्सोलमा खोल्नुहोस्

विवरणहरू

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

प्यारामिटरहरू

नामप्रकारआवश्यकयो के हो
Idempotency-Key (header)stringहैनClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

अनुरोध बडी

नामप्रकारआवश्यकयो के हो
namestringहुन्छ
scopesstring[]हैनRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanहैनMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullहैनThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

प्रतिक्रिया

नामप्रकारआवश्यकयो के हो
idUuidहुन्छUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringहुन्छ
prefixstringहुन्छThe key's public lookup id (the middle segment of the token).
scopesstring[]हुन्छThe RBAC permission keys this key may exercise.
sandboxbooleanहुन्छA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectहैनWhen the key last authenticated a request; null if never used.
revoked_atobjectहैनAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringहुन्छ
tokenstringहुन्छThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

यो इन्डपोइन्टले फर्काउन सक्ने त्रुटिहरू

401 · 403 · 409 · 422 · 429