# Create an API key (/docs/api/access/keys_create)

Mint a scoped key. The secret is returned once.

`POST /v1/keys`

```json
{
  "operationId": "keys_create",
  "summary": "Create an API key",
  "description": "Mint a scoped key. The secret is returned once.",
  "tags": [
    "keys"
  ],
  "security": [
    {
      "bearer": []
    }
  ],
  "requestBody": {
    "required": true,
    "content": {
      "application/json": {
        "schema": {
          "type": "object",
          "properties": {
            "name": {
              "type": "string",
              "minLength": 1,
              "maxLength": 80
            },
            "limit_micro": {
              "type": "integer",
              "minimum": 0,
              "description": "Spend cap for this key in micro-USD"
            },
            "limit_reset": {
              "type": "string",
              "enum": [
                "day",
                "week",
                "month",
                "never"
              ]
            },
            "scopes": {
              "type": "array",
              "items": {
                "type": "string",
                "enum": [
                  "*",
                  "call",
                  "run",
                  "jobs",
                  "lists",
                  "catalog:read",
                  "balance:read",
                  "logs:read",
                  "billing:write",
                  "keys:write",
                  "agents:write",
                  "credentials:write",
                  "presets:write",
                  "pipelines:read",
                  "pipelines:write",
                  "pipelines:run",
                  "cache:write"
                ]
              },
              "minItems": 1,
              "default": [
                "call",
                "run",
                "catalog:read",
                "balance:read"
              ]
            },
            "agent_id": {
              "type": "string",
              "minLength": 3,
              "maxLength": 64
            },
            "kind": {
              "type": "string",
              "enum": [
                "live",
                "test",
                "agent"
              ],
              "default": "live"
            },
            "expires_at": {
              "type": "string",
              "format": "date-time",
              "description": "The key stops working at this time"
            },
            "allowed_ips": {
              "type": "array",
              "items": {
                "type": "string",
                "minLength": 2,
                "maxLength": 64
              },
              "maxItems": 50,
              "description": "Only accept the key from these IPs or CIDR ranges (CF-Connecting-IP)"
            },
            "label": {
              "type": "string",
              "pattern": "^[a-z0-9_-]{1,40}$",
              "description": "Role label such as primary, backup or ci; keep a backup key for zero-downtime rotation"
            }
          },
          "required": [
            "name"
          ]
        }
      }
    }
  },
  "responses": {
    "200": {
      "description": "OK",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "object": {
                "type": "string",
                "enum": [
                  "api_key"
                ]
              },
              "id": {
                "type": "string"
              },
              "name": {
                "type": "string"
              },
              "prefix": {
                "type": "string"
              },
              "scopes": {
                "type": "array",
                "items": {
                  "type": "string",
                  "enum": [
                    "*",
                    "call",
                    "run",
                    "jobs",
                    "lists",
                    "catalog:read",
                    "balance:read",
                    "logs:read",
                    "billing:write",
                    "keys:write",
                    "agents:write",
                    "credentials:write",
                    "presets:write",
                    "pipelines:read",
                    "pipelines:write",
                    "pipelines:run",
                    "cache:write"
                  ]
                }
              },
              "status": {
                "type": "string",
                "enum": [
                  "active",
                  "revoked"
                ]
              },
              "label": {
                "type": "string"
              },
              "agent_id": {
                "type": "string"
              },
              "created_at": {
                "type": "string",
                "format": "date-time"
              },
              "last_used_at": {
                "type": "string",
                "format": "date-time"
              },
              "expires_at": {
                "type": "string",
                "format": "date-time"
              },
              "allowed_ips": {
                "type": "array",
                "items": {
                  "type": "string"
                }
              },
              "limit_micro": {
                "type": [
                  "integer",
                  "null"
                ],
                "minimum": 0
              },
              "limit_reset": {
                "type": "string",
                "enum": [
                  "day",
                  "week",
                  "month",
                  "never"
                ]
              },
              "usage_micro": {
                "type": "integer",
                "minimum": 0
              },
              "limit_remaining_micro": {
                "type": [
                  "integer",
                  "null"
                ],
                "minimum": 0
              },
              "secret": {
                "type": "string"
              }
            },
            "required": [
              "object",
              "id",
              "name",
              "prefix",
              "scopes",
              "status",
              "created_at"
            ]
          }
        }
      }
    },
    "default": {
      "description": "Error",
      "content": {
        "application/json": {
          "schema": {
            "type": "object",
            "properties": {
              "error": {
                "type": "object",
                "properties": {
                  "code": {
                    "type": "string",
                    "enum": [
                      "invalid_request",
                      "unauthorized",
                      "insufficient_balance",
                      "max_cost_exceeded",
                      "scope_denied",
                      "budget_blocked",
                      "not_found",
                      "idempotency_mismatch",
                      "invalid_meta",
                      "rate_limited",
                      "upstream_error",
                      "response_buffer_limit",
                      "provider_capacity_unavailable",
                      "grid_saturated",
                      "upstream_timeout",
                      "conflict",
                      "internal_error",
                      "account_frozen",
                      "strict_filters",
                      "plan_limit_reached",
                      "validation_failed",
                      "deadline_exceeded",
                      "cancelled"
                    ]
                  },
                  "message": {
                    "type": "string"
                  },
                  "request_id": {
                    "type": "string"
                  },
                  "call_id": {
                    "type": "string"
                  },
                  "retry_after_ms": {
                    "type": "integer",
                    "minimum": 0
                  },
                  "details": {
                    "type": "object",
                    "additionalProperties": {}
                  }
                },
                "required": [
                  "code",
                  "message"
                ]
              }
            },
            "required": [
              "error"
            ]
          }
        }
      }
    }
  }
}
```
