Skip to content
Subako Docs
Esc
navigateopen⌘Jpreview

POST /v1/api-keys

POST/v1/api-keys
Authorization
AuthorizationBearer token · headerrequired
Header parameters
Kikuvi-Workspacestring<uuid>required
Workspace to mint the key in
Idempotency-Keystring
Retry the same operation with this key to return its saved receipt. Scoped by the operation's authenticated caller or resource. A different input under the same key returns 409. Receipts are retained for at least 7 days after completion, then removed by an hourly sweep. After removal the key can execute again. Fresh-only secrets are never included in a replay.
min length 1 · max length 255
Request body
requiredapplication/json
expires_atstring<date-time> | null
labelstringrequired
max length 200
permissionsKeyPermissionSchema[]required
One of the workspace resource permissions.
Responses
200Replayed creation receipt. The secret cannot be recovered. If the first response was lost, revoke this key and mint a replacement with a new Idempotency-Key.
created_atstring<date-time>required
expires_atstring<date-time> | nullrequired
idstring<uuid>required
labelstringrequired
permissionsKeyPermissionSchema[]required
prefixstringrequired
201Minted. The secret is shown once.
created_atstring<date-time>required
expires_atstring<date-time> | nullrequired
idstring<uuid>required
labelstringrequired
permissionsKeyPermissionSchema[]required
prefixstringrequired
secretstringrequired
Shown once. Store it now; it cannot be retrieved again.
400Malformed body, an unknown or ungrantable permission, an empty permission set, a non-future expires_at, a malformed workspace header, or no workspace header.
errorErrorDetailrequired
Show properties
codeErrorCoderequired
The machine-readable half of an error response, and the field a client branches on. Closed: every error carries exactly one of these.
Allowed:unauthorizedforbiddennot_foundinvalid_requestconflictclient_outdatedprecondition_failedtoo_many_requestsinternal
messagestringrequired
401Missing, malformed, or invalid bearer token.
errorErrorDetailrequired
Show properties
codeErrorCoderequired
The machine-readable half of an error response, and the field a client branches on. Closed: every error carries exactly one of these.
Allowed:unauthorizedforbiddennot_foundinvalid_requestconflictclient_outdatedprecondition_failedtoo_many_requestsinternal
messagestringrequired
404No such workspace, or the caller cannot see it.
errorErrorDetailrequired
Show properties
codeErrorCoderequired
The machine-readable half of an error response, and the field a client branches on. Closed: every error carries exactly one of these.
Allowed:unauthorizedforbiddennot_foundinvalid_requestconflictclient_outdatedprecondition_failedtoo_many_requestsinternal
messagestringrequired
409Idempotency-Key reused with a different operation or input.
errorErrorDetailrequired
Show properties
codeErrorCoderequired
The machine-readable half of an error response, and the field a client branches on. Closed: every error carries exactly one of these.
Allowed:unauthorizedforbiddennot_foundinvalid_requestconflictclient_outdatedprecondition_failedtoo_many_requestsinternal
messagestringrequired
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST "https://api.us.cloud.subako.ai/v1/api-keys" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Kikuvi-Workspace: 497f6eca-6276-4993-bfeb-53cbbbba6f08" \
  -H "Content-Type: application/json" \
  -d '{
  "expires_at": "2019-08-24T14:15:22Z",
  "label": "string",
  "permissions": [
    "workspace.read"
  ]
}'
Response
{
  "created_at": "2019-08-24T14:15:22Z",
  "expires_at": "2019-08-24T14:15:22Z",
  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
  "label": "string",
  "permissions": [
    "workspace.read"
  ],
  "prefix": "string"
}