Create an API key
POST/v1/api-keys
Creates an API key. When project_id is set the key is scoped to that project (the default and recommended stance); omit it for an account-scoped key. capabilities narrows what the key may do; when omitted the key inherits the creator's capabilities. The raw key (nat_sk_…) is returned only in this response.
A project-scoped key requires membership of that project. The key carries no role of its own — every request it makes resolves its holder's membership again — so it can never reach past what its minter already had. An account-scoped key requires a credential that is not itself confined to one project.
A connected app cannot create keys at all: a grant is revocable and a key is not, so a key minted under a grant would still work after the app was disconnected. Reading and revoking keys stay available.
Request
Responses
- 201
- 400
- 401
- 403
API key created. The raw key value is only returned here.
The request was malformed or failed validation.
Missing or invalid credentials.
Authenticated, but not permitted to act on this key.