Ga naar inhoud

Create an API key

POST
/api/v1/api-keys
curl --request POST \
--url https://example.com/api/v1/api-keys \
--header 'Content-Type: application/json' \
--cookie bl_%3Cslug%3E_session=%3Cbl_%3Cslug%3E_session%3E \
--data '{ "name": "example", "scopes": [ "example" ], "key": "example" }'

A key for the management API (scope management), or for the gateway (scope gateway): a gateway key belongs to an app, so this creates an app that may read and write every subscription (decisions #73). The answer holds the key itself, once.

Media typeapplication/json
object
name
required
string
scopes
required

["management"] or ["gateway"].

Array<string>
key

Only for automated provisioning; normally generated.

string | null

Example generated

{
"name": "example",
"scopes": [
"example"
],
"key": "example"
}

OK.

Media typeapplication/json

A key for the management API or the gateway.

object
id
required
string
name
required
string
scopes
required
Array<string>
created_at
required
string format: date-time
last_used_at
string | null format: date-time
last4

Its last four characters, to recognise it; none for keys from before.

string | null
app_id

The app the key belongs to (decisions #73); none for the management API.

string | null
key

The key itself: only in the answer that creates it.

string | null

Example generated

{
"id": "example",
"name": "example",
"scopes": [
"example"
],
"created_at": "2026-04-15T12:00:00Z",
"last_used_at": "2026-04-15T12:00:00Z",
"last4": "example",
"app_id": "example",
"key": "example"
}

Unknown or mixed scopes, or a supplied key shorter than 16 characters.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

No valid session, DPoP-bound token or API key.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}