api-keys

POST /v1/api-keys

Create an API key.

Vituo vyote vya api-keys

Uthibitishaji

Tuma ufunguo wa API kama tokeni ya kubeba. Ufunguo lazima uwe na ruhusa ya apikeys.manage; ufunguo usio nayo unakataliwa kwa 403, si 404.

Mahali ambapo kitambulisho cha shirika lako huwekwa

Sehemu hii ya mwisho inachukua org_id kama uwanja katika mwili wa JSON.

Kitambulisho cha shirika lako kipo kwenye skrini ya funguo za API katika dashibodi yako, kando ya ufunguo wenyewe. Ni kitambulisho kile kile katika kila ombi unalofanya.

Jaribu

Badilisha chochote kilicho ndani ya mabano ya pembe na maadili yako mwenyewe, na kishikiliaji cha ufunguo na ufunguo kutoka kwa dashibodi yako.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Umeingia kwenye akaunti? Dashibodi yako ya kiweko cha API inajaza kitambulisho chako halisi cha shirika na ufunguo wako mwenyewe, na kuendesha ombi dhidi ya API ya moja kwa moja ili uweze kuona jibu halisi. Fungua sehemu hii ya mwisho (endpoint) kwenye konsole ya API

Maelezo

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Vigezo

JinaAinaInayohitajikaKilicho hiki
Idempotency-Key (header)stringHapanaClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Mwili wa ombi

JinaAinaInayohitajikaKilicho hiki
namestringNdiyo
scopesstring[]HapanaRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanHapanaMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullHapanaThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Majibu

JinaAinaInayohitajikaKilicho hiki
idUuidNdiyoUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringNdiyo
prefixstringNdiyoThe key's public lookup id (the middle segment of the token).
scopesstring[]NdiyoThe RBAC permission keys this key may exercise.
sandboxbooleanNdiyoA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectHapanaWhen the key last authenticated a request; null if never used.
revoked_atobjectHapanaAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringNdiyo
tokenstringNdiyoThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Hitilafu ambazo mwisho huu unaweza kurudisha

401 · 403 · 409 · 422 · 429