Skip to main content

Create an API key

POST 

/api-keys

Creates an API key with permissions on object types and returns the new key with a generated secret. Foundation4 returns the secret only in this response and stores only a hash, so a lost secret cannot be recovered. Permissions on individual objects are granted afterward with POST /api-keys/{api_key_id}/permissions.

Permissions. Write on the api-keys object type. Each permission in permissions must be contained in the calling key's permission on the same object type. When the calling key's allow-list on pipelines is not *, each classification in classifications must be in the calling key's allow-list.

Access control describes permissions and classification allow-lists.

Request​

Responses​

The API key was created. The body is the new key, including the generated secret in secret.