Skip to main content
POST
Mint an API key for a service account (org admin)

Authorizations

Authorization
string
header
required

Use Authorization: Bearer <token>. The token is either a user token / OAuth access token, or a service-account API key (cfk_...). A key is valid on every endpoint and acts as its service account, an organization member with per-store permissions. Refused keys answer 403 with Invalid API key., API key revoked., API key expired. or API key disabled..

Body

application/json
service_account
string<uuid>
required

The service account the key authenticates as.

name
string
expires_at
string<date-time> | null

Optional; must be in the future.

Response

Created. Includes the one-time plaintext key.

API key metadata. Never includes the secret or its stored forms.

id
string<uuid>
organization
string<uuid>
service_account
object
name
string
key_prefix
string

The 8 characters after cfk_, to recognise a key without revealing it.

status
enum<string>
Available options:
active,
expired,
revoked
created_at
string<date-time>
created_by
object | null
expires_at
string<date-time> | null
revoked_at
string<date-time> | null
last_used_at
string<date-time> | null
api_key
string

Full plaintext key — shown only here, once.