curl --request POST \
--url https://api.deapi.ai/api/v2/keys \
--header 'Accept: <accept>' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Customer 1234",
"expires_at": "2026-12-31T23:59:59Z",
"role": "api",
"ip_whitelist": [
"203.0.113.7",
"198.51.100.0/24"
],
"limit": 100,
"reset_interval": "monthly"
}
'import requests
url = "https://api.deapi.ai/api/v2/keys"
payload = {
"name": "Customer 1234",
"expires_at": "2026-12-31T23:59:59Z",
"role": "api",
"ip_whitelist": ["203.0.113.7", "198.51.100.0/24"],
"limit": 100,
"reset_interval": "monthly"
}
headers = {
"Accept": "<accept>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Accept: '<accept>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: 'Customer 1234',
expires_at: '2026-12-31T23:59:59Z',
role: 'api',
ip_whitelist: ['203.0.113.7', '198.51.100.0/24'],
limit: 100,
reset_interval: 'monthly'
})
};
fetch('https://api.deapi.ai/api/v2/keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.deapi.ai/api/v2/keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Customer 1234',
'expires_at' => '2026-12-31T23:59:59Z',
'role' => 'api',
'ip_whitelist' => [
'203.0.113.7',
'198.51.100.0/24'
],
'limit' => 100,
'reset_interval' => 'monthly'
]),
CURLOPT_HTTPHEADER => [
"Accept: <accept>",
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.deapi.ai/api/v2/keys"
payload := strings.NewReader("{\n \"name\": \"Customer 1234\",\n \"expires_at\": \"2026-12-31T23:59:59Z\",\n \"role\": \"api\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"monthly\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Accept", "<accept>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.deapi.ai/api/v2/keys")
.header("Accept", "<accept>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Customer 1234\",\n \"expires_at\": \"2026-12-31T23:59:59Z\",\n \"role\": \"api\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"monthly\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.deapi.ai/api/v2/keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Accept"] = '<accept>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Customer 1234\",\n \"expires_at\": \"2026-12-31T23:59:59Z\",\n \"role\": \"api\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"monthly\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": 43,
"name": "Customer 1234",
"preview": "43|...9bc",
"role": "api",
"status": "active",
"created_at": "2026-09-22T12:00:00+00:00",
"expires_at": null,
"last_used_at": null,
"ip_whitelist": [
"203.0.113.7",
"198.51.100.0/24"
],
"ip_whitelist_count": 2,
"limit": 100,
"reset_interval": "monthly",
"limit_used": 0,
"limit_remaining": 100,
"limit_resets_at": "2026-10-22T12:00:00+00:00",
"secret": "43|kx8…"
}
}{
"data": {},
"message": "<string>",
"errors": [
"<unknown>"
],
"statusCode": 123,
"code": "missing_key"
}{
"message": "This API key does not have permission to access this endpoint.",
"code": "insufficient_permissions"
}{
"message": "You have reached the limit of 100 active API keys — delete or deactivate the ones you no longer use.",
"code": "active_key_limit_reached"
}{
"message": "Too many API keys created recently.",
"code": "rate_limited",
"retry_after": 1800
}Create Key
Creates a key with the API role. Needs an ADMIN key; ADMIN keys can only be created in the Dashboard. The secret is returned once, in this response. Counts toward the account’s limit of active keys and the hourly limit of keys created over the API (shared by all ADMIN keys of the account). An ip_whitelist given here applies from the key’s first call.
curl --request POST \
--url https://api.deapi.ai/api/v2/keys \
--header 'Accept: <accept>' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Customer 1234",
"expires_at": "2026-12-31T23:59:59Z",
"role": "api",
"ip_whitelist": [
"203.0.113.7",
"198.51.100.0/24"
],
"limit": 100,
"reset_interval": "monthly"
}
'import requests
url = "https://api.deapi.ai/api/v2/keys"
payload = {
"name": "Customer 1234",
"expires_at": "2026-12-31T23:59:59Z",
"role": "api",
"ip_whitelist": ["203.0.113.7", "198.51.100.0/24"],
"limit": 100,
"reset_interval": "monthly"
}
headers = {
"Accept": "<accept>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
Accept: '<accept>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
name: 'Customer 1234',
expires_at: '2026-12-31T23:59:59Z',
role: 'api',
ip_whitelist: ['203.0.113.7', '198.51.100.0/24'],
limit: 100,
reset_interval: 'monthly'
})
};
fetch('https://api.deapi.ai/api/v2/keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.deapi.ai/api/v2/keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'Customer 1234',
'expires_at' => '2026-12-31T23:59:59Z',
'role' => 'api',
'ip_whitelist' => [
'203.0.113.7',
'198.51.100.0/24'
],
'limit' => 100,
'reset_interval' => 'monthly'
]),
CURLOPT_HTTPHEADER => [
"Accept: <accept>",
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.deapi.ai/api/v2/keys"
payload := strings.NewReader("{\n \"name\": \"Customer 1234\",\n \"expires_at\": \"2026-12-31T23:59:59Z\",\n \"role\": \"api\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"monthly\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Accept", "<accept>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.deapi.ai/api/v2/keys")
.header("Accept", "<accept>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"Customer 1234\",\n \"expires_at\": \"2026-12-31T23:59:59Z\",\n \"role\": \"api\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"monthly\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.deapi.ai/api/v2/keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Accept"] = '<accept>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"Customer 1234\",\n \"expires_at\": \"2026-12-31T23:59:59Z\",\n \"role\": \"api\",\n \"ip_whitelist\": [\n \"203.0.113.7\",\n \"198.51.100.0/24\"\n ],\n \"limit\": 100,\n \"reset_interval\": \"monthly\"\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": 43,
"name": "Customer 1234",
"preview": "43|...9bc",
"role": "api",
"status": "active",
"created_at": "2026-09-22T12:00:00+00:00",
"expires_at": null,
"last_used_at": null,
"ip_whitelist": [
"203.0.113.7",
"198.51.100.0/24"
],
"ip_whitelist_count": 2,
"limit": 100,
"reset_interval": "monthly",
"limit_used": 0,
"limit_remaining": 100,
"limit_resets_at": "2026-10-22T12:00:00+00:00",
"secret": "43|kx8…"
}
}{
"data": {},
"message": "<string>",
"errors": [
"<unknown>"
],
"statusCode": 123,
"code": "missing_key"
}{
"message": "This API key does not have permission to access this endpoint.",
"code": "insufficient_permissions"
}{
"message": "You have reached the limit of 100 active API keys — delete or deactivate the ones you no longer use.",
"code": "active_key_limit_reached"
}{
"message": "Too many API keys created recently.",
"code": "rate_limited",
"retry_after": 1800
}403 with code: insufficient_permissions — see API Keys.secret is returned only once, in the response to this call. Store it straight away — it cannot be read again. If it is lost, create a new key and delete the old one.429 with X-RateLimit-Type: key-creation.Authorizations
Sanctum personal access token, sent as Authorization: Bearer <token>. The token is opaque — it carries no claims and no embedded expiry, so do not attempt to decode it. Issue and revoke tokens from your account dashboard.
Headers
application/json Body
255"Customer 1234"
Optional. Leave it out for a key that never expires. A date must be in the future and no later than 2038-01-19 03:14:07 UTC, the latest instant this platform can store — a 422, not a silently shortened key.
"2026-12-31T23:59:59Z"
Only api. admin is refused with 403.
api, admin "api"
Optional. The only addresses the new key may be used from; omitted or [] means any. Duplicates and surrounding whitespace are removed, an explicit null is refused.
20["203.0.113.7", "198.51.100.0/24"]
Optional. What this key may spend per window, in USD; omitted or null means no limit. Work that would take the key past it is refused with 402 key_limit_exceeded.
0 <= x <= 999999.999999100
How often that limit starts over; none means it never does. Only accepted together with a non-null limit. Windows are anchored on the key's creation instant, not the calendar.
none, daily, weekly, monthly "monthly"
Response
The new key, with its secret.
Show child attributes
Show child attributes
Was this page helpful?