Autentificare
Trimiteți o cheie API ca token de tip bearer. Cheia trebuie să aibă permisiunea apikeys.manage; o cheie care nu o are va fi respinsă cu 403, nu 404.
Unde merge ID-ul organizației tale
Acest punct final preia org_id ca câmp în corpul JSON.
ID-ul organizației tale se află pe ecranul cheilor API din panoul de control, lângă cheia însăși. Este același ID în fiecare apel pe care îl faci.
Încearcă
Înlocuiți tot ce se află între paranteze unghiulare cu propriile valori și substituentul cheie cu o cheie din tabloul de bord.
curl -X POST https://api.zinndigital.com/v1/api-keys \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "name": <string> }'Autentificat? Consola API din panoul de control îți completează ID-ul real al organizației și propria cheie și rulează cererea în API-ul live, astfel încât să poți vedea răspunsul efectiv. Deschideți acest punct final în consola API
Detalii
Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.
Parametri
| Nume | Tip | Obligatoriu | Ce este |
|---|---|---|---|
Idempotency-Key (header) | string | Nu | Client-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats. |
Corp cerere
| Nume | Tip | Obligatoriu | Ce este |
|---|---|---|---|
name | string | Da | — |
scopes | string[] | Nu | RBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a… |
sandbox | boolean | Nu | Mint a sandbox (test-mode) key. Defaults to false. |
org_id | Uuid | null | Nu | The organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org. |
Răspuns
| Nume | Tip | Obligatoriu | Ce este |
|---|---|---|---|
id | Uuid | Da | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
name | string | Da | — |
prefix | string | Da | The key's public lookup id (the middle segment of the token). |
scopes | string[] | Da | The RBAC permission keys this key may exercise. |
sandbox | boolean | Da | A sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2). |
last_used_at | object | Nu | When the key last authenticated a request; null if never used. |
revoked_at | object | Nu | Always null on a listed/fetched key — revoked keys are not returned. |
created_at | string | Da | — |
token | string | Da | The full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced. |
Erori pe care le poate returna acest punct final
401 · 403 · 409 · 422 · 429