Docs

Mint an API key for a client; the key is shown once

  • In the sandbox

In plain words

Makes an API key for a client. The key is shown once.
POST
/keys

The operator mints for any client. A client's admin key mints only for its own client and only scopes it holds. Only the SHA-256 is kept.

Authorization

apiKey
headerAuthorizationBearer <token>

Send your key as a bearer token: Authorization: Bearer <your-api-key>. Health is the only call that needs no key.

Request body

application/json
  1. body
client?string
Match^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$
scopes*array<>
Items1 <= items
label?string
Lengthlength <= 100

Response body

Minted. key appears in this answer only.

application/json
  1. response
id*string
client*string
environment*string
Value in"sandbox""production"
scopes*array<>
label?string
created_at*string
Formatdate-time
revoked_at?string
Formatdate-time
also_revoked?array<string>

Only in a revoke answer, the ids of the keys minted under this one that were revoked with it.

key*string
Match^eik_(test|live)_[0-9a-f]{48}$
curl -X POST "https://example.com/keys" \  -H "Authorization: Bearer <your-api-key>" \  -H "Content-Type: application/json" \  -d '{    "scopes": [      "submit"    ]  }'
{  "id": "string",  "client": "string",  "environment": "sandbox",  "scopes": [    "submit"  ],  "label": "string",  "created_at": "2019-08-24T14:15:22Z",  "revoked_at": "2019-08-24T14:15:22Z",  "also_revoked": [    "string"  ],  "key": "string"}