> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.mixlayer.com/api-reference/platform-api/api-key-management/create-api-key/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.mixlayer.com/_mcp/server. # Create an API key POST https://api.mixlayer.com/v1/organizations/{org_id}/api_keys Content-Type: application/json When authenticated with an API key, this operation requires `api-admin`. Reference: https://docs.mixlayer.com/api-reference/platform-api/api-key-management/create-api-key ## Authentication - `Authorization` header (bearer token, required) — Console user session or Mixlayer API key supplied as a Bearer token. ## Request ### Path parameters - `org_id` (string, required) — Organization ID ### Body (application/json) This endpoint expects a CreateApiKeyRequest. - `expires_at` (datetime, optional, nullable) — Expiration timestamp, which must be in the future. Omit or use null for no expiration. - `name` (string, optional) — Human-readable key name. Whitespace is trimmed and the maximum length is 200 characters. - `permissions` (list of enum, optional, default: ["inference"]) — Permissions granted to the key. Defaults to `inference` and must contain at least one permission. - Allowed values: `inference`, `api-read`, `api-write`, `api-admin` ## Response ### 200 API key and its one-time secret - `data` (ApiDataResponseApiKeyWithSecretResponseData, required) — User-facing API key metadata with its one-time secret. ## Errors ### 400 Bad Request Error The request body contains malformed JSON or invalid values. - `error` (ApiErrorBody, required) — Structured error details. ### 401 Unauthorized Error Authentication is missing or invalid. - `error` (ApiErrorBody, required) — Structured error details. ### 403 Forbidden Error The authenticated principal cannot perform this operation. - `error` (ApiErrorBody, required) — Structured error details. ### 404 Not Found Error The requested resource is not visible to the authenticated principal. - `error` (ApiErrorBody, required) — Structured error details. ### 413 Content Too Large Error The request body exceeds the configured size limit. - `error` (ApiErrorBody, required) — Structured error details. ### 415 Unsupported Media Type Error The request does not have a JSON content type. - `error` (ApiErrorBody, required) — Structured error details. ### 422 Unprocessable Entity Error The JSON body does not match the request schema or contains a rejected field value. - `error` (ApiErrorBody, required) — Structured error details. ### 500 Internal Server Error An unexpected server or database error occurred. - `error` (ApiErrorBody, required) — Structured error details. ## Types ### ApiDataResponseApiKeyWithSecretResponseData User-facing API key metadata with its one-time secret. - `active` (boolean, required) — Whether the key can currently authenticate requests. - `created_at` (datetime, required) — Time the key was created. - `id` (string, required) — Stable API key identifier. - `name` (string, required) — Human-readable API key name. - `permissions` (list of enum, required) — Permission scopes granted to the key. - Allowed values: `inference`, `api-read`, `api-write`, `api-admin` - `key` (string, required) — One-time API key secret. This value is not returned again. - `expires_at` (datetime, optional, nullable) — Time the key expires, or null when it does not expire. ### ApiErrorBody Structured error details returned by the platform API. - `message` (string, required) — Human-readable error message. - `code` (string, optional, nullable) — Stable machine-readable error code, when available. - `details` (any, optional) — Error-specific structured context, when available. ## Examples **Request** ```json {} ``` **Response** ```json { "data": { "active": true, "created_at": "2024-01-15T09:30:00Z", "id": "string", "name": "string", "permissions": [ "inference" ], "key": "string", "expires_at": null } } ``` **SDK Code** ```python import requests url = "https://api.mixlayer.com/v1/organizations/org_id/api_keys" payload = {} headers = { "Authorization": "Bearer ", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api.mixlayer.com/v1/organizations/org_id/api_keys'; const options = { method: 'POST', headers: {Authorization: 'Bearer ', 'Content-Type': 'application/json'}, body: '{}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api.mixlayer.com/v1/organizations/org_id/api_keys" payload := strings.NewReader("{}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "Bearer ") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api.mixlayer.com/v1/organizations/org_id/api_keys") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = 'Bearer ' request["Content-Type"] = 'application/json' request.body = "{}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api.mixlayer.com/v1/organizations/org_id/api_keys") .header("Authorization", "Bearer ") .header("Content-Type", "application/json") .body("{}") .asString(); ``` ```php request('POST', 'https://api.mixlayer.com/v1/organizations/org_id/api_keys', [ 'body' => '{}', 'headers' => [ 'Authorization' => 'Bearer ', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ```