api

Manage the caller's own API keys.

ApiKeyAuthentication is listed so a request made with a key is recognised and then refused by IsSessionAuthenticated: a leaked key must not be able to mint more keys.

post/api/account/api-keys

Request body

namestring required

What this key is used for.

scopesstring[]

Extra permissions. Empty means read-only.

expires_in_daysstring

How long the key lasts. Omit it to get the deployment's default.

Response

Created

idinteger
namestring required

What this key is used for.

prefixstring required

Leading fragment, shown so keys can be told apart.

scopesstring[]
createdstring date-time

Creation date.

last_used_atstring date-time nullable

Last time this key authenticated a request.

expires_atstring date-time nullable

Expiry date. Null only for keys issued before expiry existed.

keystring

The key itself. It is not stored and never shown again.

Changes

Changed in 1 of the 52 revisions of this API.1