---
title: "Manage the caller's own API keys."
method: POST
path: "/api/account/api-keys"
tags: ["api"]
---

# Manage the caller's own API keys.

`POST /api/account/api-keys`

ApiKeyAuthentication is listed so a request made with a key is recognised and
then refused by IsSessionAuthenticated: a leaked key must not be able to mint
more keys.

## Request body

- ApiKeyCreate
  - `name` string, required — What this key is used for.
  - `scopes` string[] — Extra permissions. Empty means read-only.
  - `expires_in_days` string — How long the key lasts. Omit it to get the deployment's default.

## Response `201`

Created

- ApiKeyCreateResponse
  - `id` integer
  - `name` string, required — What this key is used for.
  - `prefix` string, required — Leading fragment, shown so keys can be told apart.
  - `scopes` string[]
  - `created` string, date-time — Creation date.
  - `last_used_at` string, date-time, nullable — Last time this key authenticated a request.
  - `expires_at` string, date-time, nullable — Expiry date. Null only for keys issued before expiry existed.
  - `key` string — The key itself. It is not stored and never shown again.

## Changes

- **2026-09-28** `5ebd93b1e0f1` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/bitmakerla/apis/estela-api-v1-0-documentation/changes/api/account/api-keys/post.md)

---

[API](https://skmtc.dev/bitmakerla/apis/estela-api-v1-0-documentation.md) · [All operations](https://skmtc.dev/bitmakerla/apis/estela-api-v1-0-documentation/llms.txt) · [OpenAPI document](https://skmtc.dev/bitmakerla/apis/estela-api-v1-0-documentation/revisions/eaa3dc83a89f?raw)
