Accounts the key may act on. Each must be one the caller has access to. When omitted, the key covers every account the caller can access. When provided, the key is restricted to exactly those accounts.
Per-key permission flags, scoping what an API key may do on the accounts it targets. Mirrors the granular account permissions: the effective authority on a request is these flags intersected with the user's current permissions on the requested account, so a key can never out-rank its owner.
API key created successfully