api-keys

POST /v1/api-keys

Create an API key.

Dhammaan api-keys bixiyayaasha

Xaqiijinta aqoonsiga

U dir furaha API ah calaamad dusha ah (bearer token). Furaha waa inuu wataa ruqadda apikeys.manage; furaha aan wadan waxaa loo diidayaa 403, ee ma aha 404.

Meesha aqoonsiga ururkaagu galayo

Boggan waxaa uu qaataa org_id oo ah goob ku jirta JSON body.

Aqoonsiga ururkaagu wuxuu ku yaallaa shaashada furayaasha API ee dashboard-kaaga, oo ku xiga furaha laftiisa. Waa isku aqoonsi wicitaan kasta oo aad sameyso.

Isku day

Ku beddel wax kasta oo ku dhex jira qeebaha xaglaha ah qiimayaashaada, sidoo kalena haystaaha furaha ku beddel fure ka dhex muuqda dashboordigaaga.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Ma sign-garaysay? Qalabka API ee ku jira dashboard-kaagu wuxuu buuxiyaa aqoonsigaaga ururka ee dhabta ah iyo furahaaga gaarka ah, wuxuuna ku shaqeysiiyaa codsiga API-ga nool si aad u aragto jawaabta dhabta ah. Kani ka fur barta kontoroolka ee API

Faahfaahin

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Cabiraha

MagacaNoocLoo baahan yahayMaxay tahay
Idempotency-Key (header)stringMayaClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Codsiga jidhkiisa

MagacaNoocLoo baahan yahayMaxay tahay
namestringHaa
scopesstring[]MayaRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanMayaMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullMayaThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Jawaab

MagacaNoocLoo baahan yahayMaxay tahay
idUuidHaaUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringHaa
prefixstringHaaThe key's public lookup id (the middle segment of the token).
scopesstring[]HaaThe RBAC permission keys this key may exercise.
sandboxbooleanHaaA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectMayaWhen the key last authenticated a request; null if never used.
revoked_atobjectMayaAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringHaa
tokenstringHaaThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Cilladaha ay bartaani soo celin karto

401 · 403 · 409 · 422 · 429