Create an organization API key

posthttps://api.expiryedge.com/v1/createApiKey
bearer token of a signed-in person (Firebase ID token or session JWT, not an API key); role admin60/minIdempotency-Key
Anfrage
curl -X POST 'https://api.expiryedge.com/v1/createApiKey' \
  -H "Authorization: Bearer $EXPIRYEDGE_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "name": "Nightly HR import",
  "role": "editor",
  "expires_at": "2027-01-01T00:00:00Z"
}'
Antwort
{
  "key": "ee_live_4fQ9vB2kLm8XzT1rW6yNp0sHc3dJ5gA7uE9iO2qR4tY",
  "api_key": {
    "id": "k7Qm2xKpA1",
    "name": "Nightly HR import",
    "prefix": "ee_live_4fQ9",
    "role": "editor",
    "status": "active",
    "created_by": "u_71bXq",
    "created_at": "2026-09-27T14:05:00.000Z",
    "last_used_at": null,
    "expires_at": "2027-01-01T00:00:00.000Z",
    "revoked_at": null
  }
}

Returns the full key once - only its SHA-256 hash and first 12 characters are stored. Up to 25 active keys per organization. The key authenticates as Authorization: Bearer ee_live_... or X-API-Key with the chosen role (editor or viewer). An Idempotency-Key replay returns key: null.

Header

  • Idempotency-Keystring
    Optional client-generated key (1-255 characters of letters, digits, - _ : .).
    pattern: ^[A-Za-z0-9_\-:.]{1,255}$

Body-Parameter

application/json
  • namestringerforderlich
    Label shown in Settings (HTML is stripped).
    min length: 1 · max length: 100
  • rolestring
    What the key may do. Keys can never be admin.
    ErlaubteditorviewerStandard editor
  • expires_atstring | null
    Optional future time after which the key stops working.
    format: date-time

Rückgabe

201
Key created. key is shown only in this response.
  • keystring | nullschreibgeschützt
    The full key (ee_live_ + 43 characters). Shown only once; null on an Idempotency-Key replay.
  • api_keyobject
    An organization API key without the secret. Only the first 12 characters (prefix) are ever shown again.

Fehler

400
The request is missing required fields or contains invalid values.
401
Missing, expired or invalid bearer token.
403
Authenticated, but your role or organization does not allow this action.
405
The endpoint does not accept this HTTP method.
409
The organization already has 25 active API keys (code LIMIT_REACHED).; or a request with the same Idempotency-Key is still being processed (code IDEMPOTENCY_IN_PROGRESS).
422
The Idempotency-Key was already used with a different request body.
429
Too many requests for this endpoint from your IP. Wait Retry-After seconds.
500
Unexpected server error. Retry later; quote requestId to support.