import { Textql } from "@textql/sdk";
const textql = new Textql({
apiKey: process.env["TEXTQL_API_KEY"] ?? "",
});
async function run() {
const result = await textql.rbac.createApiKey({
body: {},
});
console.log(result);
}
run();import os
from textql_sdk import Textql
with Textql(
api_key=os.getenv("TEXTQL_API_KEY", ""),
) as textql:
res = textql.rbac.create_api_key()
# Handle response
print(res)curl --request POST \
--url https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey \
--header 'Connect-Protocol-Version: <connect-protocol-version>' \
--header 'Content-Type: application/json' \
--header 'tql_api_key: <api-key>' \
--data '
{
"targetMemberEmail": "<string>",
"assumedRoleNames": [
"<string>"
],
"expirySeconds": 123,
"assumedRoles": [
"<string>"
],
"inheritAllRoles": true,
"name": "<string>",
"targetMemberId": "<string>",
"clientId": "<string>",
"suppressSuperadmin": true,
"fullMemberAccess": true
}
'const options = {
method: 'POST',
headers: {
'Connect-Protocol-Version': '<connect-protocol-version>',
tql_api_key: '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
targetMemberEmail: '<string>',
assumedRoleNames: ['<string>'],
expirySeconds: 123,
assumedRoles: ['<string>'],
inheritAllRoles: true,
name: '<string>',
targetMemberId: '<string>',
clientId: '<string>',
suppressSuperadmin: true,
fullMemberAccess: true
})
};
fetch('https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'targetMemberEmail' => '<string>',
'assumedRoleNames' => [
'<string>'
],
'expirySeconds' => 123,
'assumedRoles' => [
'<string>'
],
'inheritAllRoles' => true,
'name' => '<string>',
'targetMemberId' => '<string>',
'clientId' => '<string>',
'suppressSuperadmin' => true,
'fullMemberAccess' => true
]),
CURLOPT_HTTPHEADER => [
"Connect-Protocol-Version: <connect-protocol-version>",
"Content-Type: application/json",
"tql_api_key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey"
payload := strings.NewReader("{\n \"targetMemberEmail\": \"<string>\",\n \"assumedRoleNames\": [\n \"<string>\"\n ],\n \"expirySeconds\": 123,\n \"assumedRoles\": [\n \"<string>\"\n ],\n \"inheritAllRoles\": true,\n \"name\": \"<string>\",\n \"targetMemberId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"suppressSuperadmin\": true,\n \"fullMemberAccess\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Connect-Protocol-Version", "<connect-protocol-version>")
req.Header.Add("tql_api_key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey")
.header("Connect-Protocol-Version", "<connect-protocol-version>")
.header("tql_api_key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"targetMemberEmail\": \"<string>\",\n \"assumedRoleNames\": [\n \"<string>\"\n ],\n \"expirySeconds\": 123,\n \"assumedRoles\": [\n \"<string>\"\n ],\n \"inheritAllRoles\": true,\n \"name\": \"<string>\",\n \"targetMemberId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"suppressSuperadmin\": true,\n \"fullMemberAccess\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Connect-Protocol-Version"] = '<connect-protocol-version>'
request["tql_api_key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"targetMemberEmail\": \"<string>\",\n \"assumedRoleNames\": [\n \"<string>\"\n ],\n \"expirySeconds\": 123,\n \"assumedRoles\": [\n \"<string>\"\n ],\n \"inheritAllRoles\": true,\n \"name\": \"<string>\",\n \"targetMemberId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"suppressSuperadmin\": true,\n \"fullMemberAccess\": true\n}"
response = http.request(request)
puts response.read_body{
"apiKey": {
"id": "<string>",
"memberId": "<string>",
"clientId": "<string>",
"createdAt": "2023-01-15T01:30:15.01Z",
"apiKeyShort": "<string>",
"assumedRoleNames": [
"<string>"
],
"assumedRoles": [
"<string>"
],
"name": "<string>",
"expiresAt": "2023-01-15T01:30:15.01Z",
"revokedAt": "2023-01-15T01:30:15.01Z",
"status": "API_KEY_STATUS_UNSPECIFIED",
"ownerDisplayName": "<string>",
"ownerEmail": "<string>",
"suppressSuperadmin": true
},
"apiKeySecret": "<string>",
"apiKeyHash": "<string>"
}{
"code": "not_found",
"message": "<string>",
"details": [
{
"type": "<string>",
"value": "<string>",
"debug": {}
}
]
}Create Api Key
API Key management
import { Textql } from "@textql/sdk";
const textql = new Textql({
apiKey: process.env["TEXTQL_API_KEY"] ?? "",
});
async function run() {
const result = await textql.rbac.createApiKey({
body: {},
});
console.log(result);
}
run();import os
from textql_sdk import Textql
with Textql(
api_key=os.getenv("TEXTQL_API_KEY", ""),
) as textql:
res = textql.rbac.create_api_key()
# Handle response
print(res)curl --request POST \
--url https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey \
--header 'Connect-Protocol-Version: <connect-protocol-version>' \
--header 'Content-Type: application/json' \
--header 'tql_api_key: <api-key>' \
--data '
{
"targetMemberEmail": "<string>",
"assumedRoleNames": [
"<string>"
],
"expirySeconds": 123,
"assumedRoles": [
"<string>"
],
"inheritAllRoles": true,
"name": "<string>",
"targetMemberId": "<string>",
"clientId": "<string>",
"suppressSuperadmin": true,
"fullMemberAccess": true
}
'const options = {
method: 'POST',
headers: {
'Connect-Protocol-Version': '<connect-protocol-version>',
tql_api_key: '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
targetMemberEmail: '<string>',
assumedRoleNames: ['<string>'],
expirySeconds: 123,
assumedRoles: ['<string>'],
inheritAllRoles: true,
name: '<string>',
targetMemberId: '<string>',
clientId: '<string>',
suppressSuperadmin: true,
fullMemberAccess: true
})
};
fetch('https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'targetMemberEmail' => '<string>',
'assumedRoleNames' => [
'<string>'
],
'expirySeconds' => 123,
'assumedRoles' => [
'<string>'
],
'inheritAllRoles' => true,
'name' => '<string>',
'targetMemberId' => '<string>',
'clientId' => '<string>',
'suppressSuperadmin' => true,
'fullMemberAccess' => true
]),
CURLOPT_HTTPHEADER => [
"Connect-Protocol-Version: <connect-protocol-version>",
"Content-Type: application/json",
"tql_api_key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey"
payload := strings.NewReader("{\n \"targetMemberEmail\": \"<string>\",\n \"assumedRoleNames\": [\n \"<string>\"\n ],\n \"expirySeconds\": 123,\n \"assumedRoles\": [\n \"<string>\"\n ],\n \"inheritAllRoles\": true,\n \"name\": \"<string>\",\n \"targetMemberId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"suppressSuperadmin\": true,\n \"fullMemberAccess\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Connect-Protocol-Version", "<connect-protocol-version>")
req.Header.Add("tql_api_key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey")
.header("Connect-Protocol-Version", "<connect-protocol-version>")
.header("tql_api_key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"targetMemberEmail\": \"<string>\",\n \"assumedRoleNames\": [\n \"<string>\"\n ],\n \"expirySeconds\": 123,\n \"assumedRoles\": [\n \"<string>\"\n ],\n \"inheritAllRoles\": true,\n \"name\": \"<string>\",\n \"targetMemberId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"suppressSuperadmin\": true,\n \"fullMemberAccess\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.textql.com/rpc/public/textql.rpc.public.rbac.RBACService/CreateApiKey")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Connect-Protocol-Version"] = '<connect-protocol-version>'
request["tql_api_key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"targetMemberEmail\": \"<string>\",\n \"assumedRoleNames\": [\n \"<string>\"\n ],\n \"expirySeconds\": 123,\n \"assumedRoles\": [\n \"<string>\"\n ],\n \"inheritAllRoles\": true,\n \"name\": \"<string>\",\n \"targetMemberId\": \"<string>\",\n \"clientId\": \"<string>\",\n \"suppressSuperadmin\": true,\n \"fullMemberAccess\": true\n}"
response = http.request(request)
puts response.read_body{
"apiKey": {
"id": "<string>",
"memberId": "<string>",
"clientId": "<string>",
"createdAt": "2023-01-15T01:30:15.01Z",
"apiKeyShort": "<string>",
"assumedRoleNames": [
"<string>"
],
"assumedRoles": [
"<string>"
],
"name": "<string>",
"expiresAt": "2023-01-15T01:30:15.01Z",
"revokedAt": "2023-01-15T01:30:15.01Z",
"status": "API_KEY_STATUS_UNSPECIFIED",
"ownerDisplayName": "<string>",
"ownerEmail": "<string>",
"suppressSuperadmin": true
},
"apiKeySecret": "<string>",
"apiKeyHash": "<string>"
}{
"code": "not_found",
"message": "<string>",
"details": [
{
"type": "<string>",
"value": "<string>",
"debug": {}
}
]
}Authorizations
Headers
Define the version of the Connect protocol
1 Define the timeout, in ms
Body
Email within the caller's organization; case-insensitive, with outer whitespace ignored. Use instead of target_member_id; if both are supplied they must identify the same member.
Exact, case-sensitive role names in the caller's organization. Merged with legacy assumed_roles IDs and deduplicated. The existing member-role and calling API-key scope restrictions apply to both forms.
Role IDs (UUIDs) to scope the new API key to. The service validates that each ID exists in the caller's org. Non-admin callers may only specify roles they already hold; assumed-role API key callers may only specify a subset of their current assumed roles. Legacy role IDs. Prefer assumed_role_names.
When true, the API key inherits all of the creating member's roles (no assumed-role scoping). Callers must set this explicitly when both role lists are empty; otherwise the request is rejected to prevent accidentally creating over-privileged keys.
Optional display name for the API key.
Optional owner override for the new API key. If unset, the API key is created for the calling member. If set, the API key is created for this member ID (target principal): service-account targets require the caller to hold organization:write; human targets require api_access_key:delegate, and the key is bounded by the target member's roles with superadmin elevation always suppressed.
Optional client metadata stored on the API key as client_id. Prefer a JSON object string when using structured client attributes.
When true, requests authenticated with this key skip the @textql.com-email superadmin elevation branch. Only meaningful when paired with assumed_roles so a textql admin can preview a role's experience without superadmin permissions bleeding through.