---
title: "Create agent key"
method: POST
path: "/agent-keys"
tags: ["Agent Keys"]
---

# Create agent key

`POST /agent-keys`

Create a new agent key bound to an existing agent. The full secret is returned only once. Creating a replacement key does not revoke existing keys — rotation overlaps until the old key is revoked.

## Headers

- `X-Agent-ID` string, nullable
- `X-Instance-ID` string, nullable

## Request body

- object
  - `data` object, required
    - `attributes` object, required
    - `relationships` object, required
      - `agent` object, required — Existing agent the key is bound to
        - `data` object, required — Related resource identifier
          - `type` 'agent', required — Resource type
          - `id` string, required

## Response `201`

Successful Response

- object
  - `data` object, required
    - `type` 'agentKey', required — Resource type
    - `id` string, required — Resource ID (agk_*)
    - `attributes` object, required — Resource attributes
      - `agentKeyPrefix` string, required — Non-secret prefix of the agent key, e.g. `ak_ntl_live_abc123`. The final segment is random.
      - `status` 'ACTIVE' | 'REVOKED', required — Status (ACTIVE or REVOKED)
      - `createdAt` string, date-time, required — When this key was created
      - `lastUsedAt` string, date-time, nullable, required — When this key was last used
      - `revokedAt` string, date-time, nullable, required — When this key was revoked
      - `createdBy` string, nullable, required — User who created this key (usr_*)
      - `revokedBy` string, nullable, required — User who revoked this key (usr_*)
      - `expiresAt` string, date-time, nullable, required — When this key stops authenticating, or null if it has no scheduled expiration
      - `agentKey` string, required — Full agent key secret (shown only once - store securely!)
    - `relationships` object, required — Resource relationships
      - `party` object, required — Party that owns the agent key
        - `data` object, required — Related resource identifier
          - `type` 'party', required — Resource type
          - `id` string, required
      - `agent` object, required — Agent this key is bound to
        - `data` object, required — Related resource identifier
          - `type` 'agent', required — Resource type
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found — returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

---

[API](https://skmtc.dev/natural/apis/natural-api.md) · [All operations](https://skmtc.dev/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/natural/natural-api/revisions/8cc2aed45847/schema)
