Skip to main content
POST
Create an API key

Authorizations

Authorization
string
header
required

API key: Authorization: Bearer sk_test_... or sk_live_....

Headers

Invoice-Version
string

Pin a dated API release (Stripe-style). Omit to use the current version. An unknown value returns 400 request.invalid_version. Echoed back on every response.

Example:

"2026-07-10"

Invoice-Account
string

Connect: act on behalf of one of your connected accounts (its acct_…/org_… id). Omit to act as your own organization. Not honored on /v1/api_keys.

Example:

"org_2P9connectedacct"

Idempotency-Key
string

Safely retry any POST. The first response is stored for 24h and replayed byte-for-byte for identical retries (the replay adds an idempotent-replayed: true header). Reusing the key with a different body is 409 idempotency.key_reuse; an in-flight duplicate is 409 idempotency.key_processing. This makes retrying a 502/429 safe — no duplicate stamp.

Example:

"a1b2c3d4-e5f6-4789-8abc-1234567890ab"

Body

application/json
mode
enum<string>
required

Environment this key stamps against: "test" (simulated) or "live" (real SAT). Independent of the requesting key's mode.

Available options:
test,
live
name
string

Human label for the key, e.g. "backend-prod" or "ci".

Required string length: 1 - 100

Response

Default Response

object
enum<string>
required

Always "api_key".

Available options:
api_key
id
string
required

API-key id, e.g. "ak_2P9K3sample".

name
string | null
required

Human label, or null if unset.

mode
enum<string>
required

Environment this key stamps against: "test" or "live".

Available options:
test,
live
prefix
string
required

Non-secret key prefix, e.g. "sk_live_ab12".

key
string
required

Plaintext secret, e.g. "sk_live_…" — shown exactly once. Store it now; it cannot be retrieved again.

created_at
string
required

Creation timestamp, ISO-8601 UTC.

revoked_at
null
required

Always null on creation.

version
string | null
required

Pinned dated API version, or null.