Skip to main content
POST
Create API Key

Authorizations

Authorization
string
header
required

API key or JWT token

Body

application/json
expirySeconds
integer

Optional TTL in seconds. Omit for a non-expiring key; short-lived keys are recommended for per-session embedding flows.

Example:

3600

assumedRoles
string[]

Role UUIDs to scope the key to. Callers may only specify roles they hold; API-key callers may only specify a subset of their own assumed roles.

Example:
inheritAllRoles
boolean

Set to true to inherit all of the creating member's roles. Required when assumedRoles is empty.

name
string

Optional display name for the key.

Example:

"acme-session-key"

targetMemberId
string

Mint the key for this member instead of the caller. A human target requires the caller's role to hold api_access_key:delegate; organization:write alone is denied. A service-account target requires organization:write. The key authenticates as the target member, always carries full member access so the target's direct object grants stay reachable, is scoped to that member's roles, and suppresses superadmin elevation. Granting api_access_key:delegate is a full impersonation capability.

clientId
string

Optional client metadata stored on the key. Prefer a JSON object string (a JSON-encoded string, not a nested object); TQL row-level security reads its fields as _tql.client_attributes_json.<field>.

Example:

"{\"tenant_id\": \"acme\", \"user_email\": \"jane@acme.example\"}"

fullMemberAccess
boolean

When true, the key keeps the target member's direct object grants alongside its assumed-role grants. A key minted on behalf of a human member always carries full member access regardless of this flag. For a key acting as the caller or as a service account, false is the default and an API-key caller may set it true only when its own key already has full member access.

Response

The created key. key is the bearer secret, shown only once.

key
string

The full bearer credential. Shown exactly once; store it securely. Use as Authorization: Bearer <key>.

Example:

"BEARER_SECRET_SHOWN_ONCE"

api_key
object