Skip to main content
POST
Create API key

Authorizations

Authorization
string
header
required

Use a JWT bearer token or a Veryfront API key in the Authorization header.

Body

application/json
name
string
required
Required string length: 1 - 255
project_reference
string
project_id
string

Deprecated project ID or slug alias. Use project_reference.

projectId
string

Deprecated camelCase project ID or slug alias. Use project_reference.

scopes
string[]
expires_at
string

Response

API key created successfully

id
string<uuid>
required
project_id
string<uuid> | null
required
user_id
string<uuid>
required
name
string
required
key
string
required
key_prefix
string
required
expires_at
string | null
required
created_at
string
required
scopes
string[]
required
scope
enum<string>
required

Whether the key is restricted to one project or applies to the account. An account-wide key acts with its owner’s project roles, limited by the key’s scopes. Unlike project-scoped keys, it can inherit the owner’s administrative authority: write can allow API key creation, and delete can allow project deletion.

Available options:
account,
project