api-keys

POST /v1/api-keys

Create an API key.

Barcha api-keys yakuniy nuqtalari

Autentifikatsiya

API kalitini bearer token sifatida yuboring. Kalit apikeys.manage ruxsatiga ega boʻlishi shart; ruxsatsiz kalit 404 emas, balki 403 xatosi bilan rad etiladi.

Tashkilotingiz identifikatori kiritiladigan joy

Ushbu so'rov JSON tanasida org_id ni maydon sifatida qabul qiladi.

Tashkilotingiz identifikatori boshqaruv panelingizdagi API kalitlari ekranida, kalitning o'z yonida joylashgan. Bu siz amalga oshiradigan har bir so'rovda bir xil identifikator hisoblanadi.

Sinab ko'rish

Qavslardagi har qanday narsani o'z qiymatlaringiz bilan, kalit pleysxolderini эsa boshqaruv panelingizdagi kalit bilan almashtiring.

curl -X POST https://api.zinndigital.com/v1/api-keys \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "name": <string> }'

Tizimga kirganmisiz? Boshqaruv panelingizdagi API konsoli haqiqiy tashkilot ID raqamingiz va shaxsiy kalitingizni avtomatik to'ldiradi hamda haqiqiy javobni ko'rishingiz uchun so'rovni jonli API orqali bajaradi. Ushbu yakuniy nuqtani API konsolida oching

Tafsilotlar

Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.

Parametrlar

NomiTuriMajburiyNima bu
Idempotency-Key (header)stringYo'qClient-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats.

Soʻrov tanasi

NomiTuriMajburiyNima bu
namestringHa
scopesstring[]Yo'qRBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a…
sandboxbooleanYo'qMint a sandbox (test-mode) key. Defaults to false.
org_idUuid | nullYo'qThe organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org.

Javob

NomiTuriMajburiyNima bu
idUuidHaUUIDv7 identifier — sortable by creation time (docs/02 §8).
namestringHa
prefixstringHaThe key's public lookup id (the middle segment of the token).
scopesstring[]HaThe RBAC permission keys this key may exercise.
sandboxbooleanHaA sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2).
last_used_atobjectYo'qWhen the key last authenticated a request; null if never used.
revoked_atobjectYo'qAlways null on a listed/fetched key — revoked keys are not returned.
created_atstringHa
tokenstringHaThe full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced.

Ushbu yakuniy nuqta qaytarishi mumkin bo'lgan xatolar

401 · 403 · 409 · 422 · 429