Create an API key
POST/api-keys
Creates an API key with permissions on object types and returns the new key with a generated secret. Foundation4 returns the secret only in this response and stores only a hash, so a lost secret cannot be recovered. Permissions on individual objects are granted afterward with POST /api-keys/{api_key_id}/permissions.
Permissions. Write on the api-keys object type. Each permission in permissions must be contained in the calling key's permission on the same object type. When the calling key's allow-list on pipelines is not *, each classification in classifications must be in the calling key's allow-list.
Access control describes permissions and classification allow-lists.
Request
Responses
- 201
- 401
- 403
- 409
- 422
The API key was created. The body is the new key, including the generated secret in secret.
The authentication headers are missing or invalid, or the API key is inactive or expired. Errors lists the messages.
The calling key lacks write permission on the api-keys object type, or requests a permission or classification that the calling key does not hold (Unauthorized: access level ... required for Api Key with id None). The same status is returned when the license is not valid (Invalid license: ...) or the license limit for API keys is reached (License limits exceeded for Api Key).
An API key with the same name exists (Conflict unique error).
The body does not match the request schema, for example a permission value outside 0 to 7 or an unknown object type. The response body is plain text.