Skip to main content
POST
Create an admin API key (shown once)

Authorizations

hookie_session
string
cookie
required

The console's sealed session cookie, set by WorkOS AuthKit. Mutating requests also require the X-Requested-With CSRF header.

Body

application/json
name
string
required
Required string length: 1 - 80
role
enum<string>
required
Available options:
viewer,
developer,
admin
project_id
string | null

Limit the key to one project's projects/{id}/… routes. Omit or null for every project.

expires_at
string | null

ISO 8601, in the future. Omit or null for no expiry.

ip_allowlist
string[] | null

IPs or CIDRs (v4 or v6). Empty or null: any address. Other addresses get 403.

Maximum array length: 64

Response

Created. key is in this response and nowhere else, ever.

id
string
required
key
string
required

hk_ followed by 48 hex characters.

Example:

"hk_3f9a1c2e…"

key_prefix
string
required
name
string
required
role
enum<string>
required
Available options:
viewer,
developer,
admin
project_id
string | null
required
expires_at
string | null
required
ip_allowlist
string[]
required
created_at
string
required