api-keys

POST /v1/api-keys

Create an API key.

Ҳамаи нуқтаҳои ниҳоии api-keys

Санҷиши ҳаққоният

Kaliti API-ро ҳамчун рамзи доранда (bearer token) фиристед. Калит бояд дорои иҷозати apikeys.manage бошад; калиди бидуни он бо хатои 403 рад карда мешавад, на 404.

Ҷое, ки рақами мушаххаси ташкилоти шумо ҷойгир аст

Ин нуқтаи поёнӣ org_id -ро ҳамчун майдон дар бадани JSON мегирад.

Rakami муайянкунандаи ташкилоти шумо дар экрани калидҳои API дар панели идоракунии шумо, дар паҳлӯи худи калид ҷойгир аст. Ин як раками муайянкунанда дар ҳар یک дархосте, ки шумо иҷро мекунед, якхела аст.

Санҷидан

Ҳар чизро дар қаavски кунҷӣ бо қиматҳои худ ва ҷойи нигоҳдорандаи калидро бо калима аз панели идоракунии худ иваз кунед.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Воarid шудаед? Консоли API дар панели идоракунии шумо рақами мушаххаси ташкилоти воқеӣ ва калиди худро пур мекунад ва дархостро бар зидди API-и фаъол иҷро мекунад, то шумо посухи воқеиро бубинед. Ин нуқтаи ниҳоиро дар консоли API кушоед

Тафсилот

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Параметрҳо

НомНамудТалаб карда мешавадИн чӣ аст
Idempotency-Key (header)stringНеClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Ҷисми дархост

НомНамудТалаб карда мешавадИн чӣ аст
namestringБале
scopesstring[]НеRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanНеMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullНеThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Ҷавоб

НомНамудТалаб карда мешавадИн чӣ аст
idUuidБалеUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringБале
prefixstringБалеThe key's public lookup id (the middle segment of the token).
scopesstring[]БалеThe RBAC permission keys this key may exercise.
sandboxbooleanБалеA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectНеWhen the key last authenticated a request; null if never used.
revoked_atobjectНеAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringБале
tokenstringБалеThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Хатоҳое, ки ин нуқтаи ниҳоӣ метавонад баргардонад

401 · 403 · 409 · 422 · 429