Skip to main content
POST
Confirm your deployment before running this request. This page describes an API contract; a published reference does not establish hosted availability. Check the dated host report and obtain your deployment URL and credentials. Replace the example host if your provisioned service uses a different URL.
Create a new API key for the calling tenant. Requires the admin scope on the calling key — non-admin keys can only read and use keys, not mint new ones. The plaintext is returned once in this response and never again; lose it and the only path forward is to delete and re-create.

Request body

CreateAPIKeyRequest
string
required
Human-readable label, e.g. ‘CI bot’ or ‘Slack integration’. Minimum length: 1. Maximum length: 128.
string[]
Allowed scopes. Empty list = full-access (back-compat). Otherwise must be a subset of: trigger:write, jobs:read, jobs:write, admin.
integer
Per-key request budget. Range 1..10000. Default: 60. Minimum: 1. Maximum: 10000.

Response

CreateAPIKeyResponse
string
required
string
required
string
required
Plaintext API key — store it now. The platform only retains the SHA-256 hash; this is the one and only time the secret is exposed.
string
required
string[]
required
integer
required
string
required

Status codes

Using this contract

Read the source OpenAPI document for declared schemas and alternatives. This page also includes documented corrections from the spec overlays. Example IDs and values are illustrative; replace them with records from your workspace.
Last modified on September 21, 2026