---
title: "Create an expiring API key"
method: POST
path: "/api-keys/expiring"
tags: ["api-keys"]
---

# Create an expiring API key

`POST /api-keys/expiring`

Issues an API key that expires at a caller-selected time. Exactly one of `expires_at` or `ttl` is required. The plaintext key is returned only for the first successful request. If that response is lost, repeating the same request and Idempotency-Key returns `credential_already_created` with the non-secret key ID; revoke that key and retry with a new Idempotency-Key.

## Headers

- `Idempotency-Key` string, required

## Request body

- union
  - object
    - `name` string, required — Name of the API key
    - `description` string — Description of the API key
    - `scopes` IssuableApiKeyScope[], required — Scopes granted to the issued key. Must be a subset of the caller's scopes.
    - `key_kind` 'personal' | 'service_account', required — Principal binding of the issued API key.
    - `expires_at` string, date-time, required — Absolute expiration time. Mutually exclusive with `ttl`.
    - `ttl` integer — Lifetime in seconds. Mutually exclusive with `expires_at`.
  - object
    - `name` string, required — Name of the API key
    - `description` string — Description of the API key
    - `scopes` IssuableApiKeyScope[], required — Scopes granted to the issued key. Must be a subset of the caller's scopes.
    - `key_kind` 'personal' | 'service_account', required — Principal binding of the issued API key.
    - `expires_at` string, date-time — Absolute expiration time. Mutually exclusive with `ttl`.
    - `ttl` integer, required — Lifetime in seconds. Mutually exclusive with `expires_at`.

## Response `201`

Expiring API key created

- CreatedExpiringApiKey
  - `id` string, uuid, required — API key ID
  - `name` string, required — Name of the API key
  - `description` string — Description of the API key
  - `key` string, required — Plaintext API key. Returned only for the first successful request.
  - `scopes` IssuableApiKeyScope[], required — Scopes granted to this key
  - `key_kind` 'personal' | 'service_account', required — Principal binding of the issued API key.
  - `creation_time` string, date-time, required — API key creation time
  - `expires_at` string, date-time, required — API key expiration time

## Other responses

- `400` — Invalid request
- `401` — Missing or invalid API key
- `403` — Scope or principal policy denied the request
- `409` — Idempotency conflict or an unrecoverable plaintext response
- `429` — Rate limit exceeded
- `500` — Internal Server Error
- `503` — Authentication or rate-limit store unavailable

## Changes

> 76 revisions in range; 20 not diffed.

- **2026-09-11** `0375753f8ee3` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/qlonolink/apis/qaip-apis/changes/api-keys/expiring/post.md)

---

[API](https://skmtc.dev/qlonolink/apis/qaip-apis.md) · [All operations](https://skmtc.dev/qlonolink/apis/qaip-apis/llms.txt) · [OpenAPI document](https://skmtc.dev/qlonolink/apis/qaip-apis/revisions/c4ae2348acf6?raw)
