Skip to main content
POST
Create an API key
Requires an ADMIN key. An API key gets 403 with code: insufficient_permissions — see API Keys.
Create a new API key, optionally with an expiration date, spend limit, reset window and IP allowlist. ADMIN keys can only be created in the Dashboard.
The secret is returned only once, in the response to this call. Store it straight away — it cannot be read again. If it is lost, create a new key and delete the old one.
Keys created over the API count toward the account limit of 100 active keys. Creating keys is also rate-limited per account: too many in an hour returns 429 with X-RateLimit-Type: key-creation.

Authorizations

Authorization
string
header
required

Sanctum personal access token, sent as Authorization: Bearer <token>. The token is opaque — it carries no claims and no embedded expiry, so do not attempt to decode it. Issue and revoke tokens from your account dashboard.

Headers

Accept
enum<string>
default:application/json
required
Available options:
application/json

Body

application/json
name
string
required
Maximum string length: 255
Example:

"Customer 1234"

expires_at
string<date-time> | null

Optional. Leave it out for a key that never expires. A date must be in the future and no later than 2038-01-19 03:14:07 UTC, the latest instant this platform can store — a 422, not a silently shortened key.

Example:

"2026-12-31T23:59:59Z"

role
enum<string>

Only api. admin is refused with 403.

Available options:
api,
admin
Example:

"api"

ip_whitelist
string[]

Optional. The only addresses the new key may be used from; omitted or [] means any. Duplicates and surrounding whitespace are removed, an explicit null is refused.

Maximum array length: 20
Example:
limit
number<float> | null

Optional. What this key may spend per window, in USD; omitted or null means no limit. Work that would take the key past it is refused with 402 key_limit_exceeded.

Required range: 0 <= x <= 999999.999999
Example:

100

reset_interval
enum<string>
default:none

How often that limit starts over; none means it never does. Only accepted together with a non-null limit. Windows are anchored on the key's creation instant, not the calendar.

Available options:
none,
daily,
weekly,
monthly
Example:

"monthly"

Response

The new key, with its secret.

data
object