Create an API key

Create a key so your own systems can talk to Dual without anybody signing in. **Save the secret now.** It appears in this response and nowhere else. If it is lost, the key cannot be recovered — delete it and make another. **A key can never do more than you can.** Ask for something your own role does not allow and the request comes back as `403`. Give each key the smallest set of permissions that does its job. **How long it lasts.** `ttl_hours` sets the lifetime, up to a year, which is also what you get if you leave it out. When a key expires it simply stops working; there is no renewal, so plan to replace keys rather than extend them. You can hold ten keys at a time. An eleventh comes back as `400`. Requires the `api-keys.create` permission.

POST
/api-keys
AuthorizationBearer <token>

The access token returned after a successful sign-in, sent as Authorization: Bearer <access_token>.

It identifies the person and the organization they are working in, and it lasts about fifteen minutes. When it runs out, use their refresh token at POST /auth/refresh-token instead of asking them to sign in again.

In: header

Request Body

application/json

The key to create.

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://api.dual.network/api-keys" \  -H "Content-Type: application/json" \  -d '{    "name": "ci-deploy",    "ttl_hours": 720,    "permissions": [      {        "resource": "objects",        "crud": {          "read": true,          "create": false,          "update": false,          "delete": false        }      }    ]  }'
{
  "id": "665f1c2d4b1a2c3d4e5f6a60",
  "secret": "<the key secret, shown only here>"
}

{
  "code": 3,
  "message": "API key limit reached"
}

{
  "code": 16,
  "message": "no auth provided"
}

{
  "code": 7,
  "message": "api key permissions exceed your own"
}
{
  "code": 13,
  "message": "internal error"
}