Service Keys

Create service key

Changed on

Create a new service role key for admin operations.

WARNING: Service keys bypass all RLS policies! Store securely and NEVER expose in frontend code.

post/projects/{id}/service-keys

Request

  • Base URL: https://api.volcano.dev
  • URL: https://api.volcano.dev/projects/{id}/service-keys
  • Auth: one of:
    • HTTP bearer
    • HTTP bearer

Path parameters

idstring uuid required

Project ID

Request body

namestring required

Descriptive name for the key (e.g., "admin-dashboard", "background-jobs"). Can only contain letters, numbers, underscores, and hyphens.

permissionsstring[]

Optional least-privilege scope for the key. When omitted, empty, or containing only blank strings, the key is granted full access ([""]) for backward compatibility. Provide an explicit list (e.g. ["functions.invoke", "locks.manage"]) to restrict the key; "" grants everything. Scope enforcement applies to function invocation, storage object operations, and project locks.

Example request

{
  "name": "admin-dashboard",
  "permissions": [
    "functions.invoke",
    "locks.manage"
  ]
}

Response

Service key created - save the key_value immediately!

idstring uuid required
project_idstring uuid
namestring required

Descriptive name for the key

key_valuestring

Full JWT token for Authorization header. Returned on create, get, and list (decrypted from storage). Store securely - NEVER expose in frontend code!

key_prefixstring required

First 12 characters of the key for display/identification

permissionsstring[] required

Operations this key may perform. ["*"] grants full admin access (default for keys created without an explicit scope). Scoped keys list specific permissions, e.g. ["functions.invoke", "locks.manage"].

created_atstring date-time
updated_atstring date-time

Example response

{
  "permissions": [
    "*"
  ]
}

Changes

    • ○

      the endpoint scheme security ProjectAccessToken was added to the API

    • ▲

      added the new path request parameter id

    • ▲

      the response's body type changed from no type to object for status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the optional property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status

    • ○

      added the required property to the response with the status