curl --request POST \
--url https://app.hookie.ai/admin/api/api-keys \
--header 'Content-Type: application/json' \
--cookie hookie_session= \
--data '
{
"name": "<string>",
"project_id": "<string>",
"expires_at": "<string>",
"ip_allowlist": [
"<string>"
]
}
'const options = {
method: 'POST',
headers: {cookie: 'hookie_session=', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
project_id: '<string>',
expires_at: '<string>',
ip_allowlist: ['<string>']
})
};
fetch('https://app.hookie.ai/admin/api/api-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/admin/api/api-keys"
payload = {
"name": "<string>",
"project_id": "<string>",
"expires_at": "<string>",
"ip_allowlist": ["<string>"]
}
headers = {
"cookie": "hookie_session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "<string>",
"key": "hk_3f9a1c2e…",
"key_prefix": "<string>",
"name": "<string>",
"role": "viewer",
"project_id": "<string>",
"expires_at": "<string>",
"ip_allowlist": [
"<string>"
],
"created_at": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Create an admin API key (shown once)
A person in the console only: a connected agent or another API key is refused, so one credential cannot mint a lasting foothold. The key never has more access than its creator, is re-clipped to the creator’s current role on every request, and stops working if they leave. Does not accept Idempotency-Key (400): the response is a secret that is never stored.
curl --request POST \
--url https://app.hookie.ai/admin/api/api-keys \
--header 'Content-Type: application/json' \
--cookie hookie_session= \
--data '
{
"name": "<string>",
"project_id": "<string>",
"expires_at": "<string>",
"ip_allowlist": [
"<string>"
]
}
'const options = {
method: 'POST',
headers: {cookie: 'hookie_session=', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: '<string>',
project_id: '<string>',
expires_at: '<string>',
ip_allowlist: ['<string>']
})
};
fetch('https://app.hookie.ai/admin/api/api-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.hookie.ai/admin/api/api-keys"
payload = {
"name": "<string>",
"project_id": "<string>",
"expires_at": "<string>",
"ip_allowlist": ["<string>"]
}
headers = {
"cookie": "hookie_session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "<string>",
"key": "hk_3f9a1c2e…",
"key_prefix": "<string>",
"name": "<string>",
"role": "viewer",
"project_id": "<string>",
"expires_at": "<string>",
"ip_allowlist": [
"<string>"
],
"created_at": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}{
"error": "<string>",
"retry_after": 123,
"upgrade_url": "<string>",
"reason": "<string>",
"code": "agent_scope_insufficient",
"required_scope": "hookie:read",
"granted_scopes": [
"<string>"
],
"manage_url": "<string>",
"scheme": "<string>"
}Authorizations
The console's sealed session cookie, set by WorkOS AuthKit. Mutating requests also require the X-Requested-With CSRF header.
Body
1 - 80viewer, developer, admin Limit the key to one project's projects/{id}/… routes. Omit or null for every project.
ISO 8601, in the future. Omit or null for no expiry.
IPs or CIDRs (v4 or v6). Empty or null: any address. Other addresses get 403.
64Response
Created. key is in this response and nowhere else, ever.
hk_ followed by 48 hex characters.
"hk_3f9a1c2e…"
viewer, developer, admin