Xác thực
Gửi khóa API dưới dạng mã thông báo bearer. Khóa này phải có quyền apikeys.manage; khóa không có quyền này sẽ bị từ chối với mã lỗi 403, không phải 404.
Nơi điền id tổ chức của bạn
Endpoint này nhận org_id làm một trường trong phần thân JSON.
Mã tổ chức của bạn nằm ở màn hình khóa API trong bảng điều khiển, ngay bên cạnh khóa đó. Đây là cùng một mã trong mọi lệnh gọi mà bạn thực hiện.
Dùng thử
Thay thế bất kỳ nội dung nào trong ngoعل (angle brackets) bằng giá trị của riêng bạn và trình giữ chỗ key bằng một key từ trang tổng quan của bạn.
curl -X POST https://api.zinndigital.com/v1/api-keys \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "name": <string> }'Đã đăng nhập? Bảng điều khiển API trong trang quản lý của bạn sẽ tự điền ID tổ chức thực tế và khóa của riêng bạn, sau đó chạy yêu cầu đối với API trực tiếp để bạn có thể xem phản hồi thực tế. Mở điểm cuối này trong bảng điều khiển API
Chi tiết
Mints a new per-org API key and returns the full `zdk_…` token **once** — only its hash is stored, so a lost token is replaced, never recovered. The requested `scopes` must be permissions the caller already holds in the target org; asking for one you do not hold is a `403` (a key can never out-scope its creator). Send an `Idempotency-Key` so a retry after a lost response returns the same token rather than orphaning a key. Requires `apikeys.manage`.
Tham số
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
Idempotency-Key (header) | string | Không | Client-generated key that makes an unsafe request replay-safe: the server stores the first response and returns it verbatim for repeats. |
Nội dung yêu cầu
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
name | string | Có | — |
scopes | string[] | Không | RBAC permission keys to grant. Each must be a permission the caller holds in the target org (a key can never out-scope its creator); an unheld scope is a `403`, an unknown one a… |
sandbox | boolean | Không | Mint a sandbox (test-mode) key. Defaults to false. |
org_id | Uuid | null | Không | The organization the key belongs to. Defaults to the caller's org; the caller must hold `apikeys.manage` in the target org. |
Phản hồi
| Tên | Loại | Bắt buộc | Nội dung này là gì |
|---|---|---|---|
id | Uuid | Có | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
name | string | Có | — |
prefix | string | Có | The key's public lookup id (the middle segment of the token). |
scopes | string[] | Có | The RBAC permission keys this key may exercise. |
sandbox | boolean | Có | A sandbox (test-mode) key suppresses billing + provisioning (docs/09 §2). |
last_used_at | object | Không | When the key last authenticated a request; null if never used. |
revoked_at | object | Không | Always null on a listed/fetched key — revoked keys are not returned. |
created_at | string | Có | — |
token | string | Có | The full `zdk_<mode>_<prefix>_<secret>` token. Shown **once, here only** — store it now; it cannot be retrieved again, only replaced. |
Các lỗi điểm cuối này có thể trả về
401 · 403 · 409 · 422 · 429