---
title: "Create a new API key"
method: POST
path: "/api/token/"
---

# Create a new API key

`POST /api/token/`

Create an API key for the authenticated account. The response confirms success but does not include the new key record or key value; call the list endpoint after creation to read the record.

## Request body

- CreateApiKeyRequest
  - `name` string — User-readable display name for the API key. The backend accepts up to 50 Unicode characters; longer names return `success: false` with `token name is too long`.
  - `expired_time` integer — Unix timestamp in seconds when the key expires. Use `-1` for no expiration. A past timestamp blocks model requests with this key.
  - `remain_quota` integer — Starting quota for the new key in CometAPI internal quota units. If this reaches `0` while `unlimited_quota` is `false`, model requests with this key are rejected as quota exhausted.
  - `unlimited_quota` boolean — Whether the key bypasses remaining-quota checks. Set `true` only when the key should keep working even if `remain_quota` is `0`.
  - `model_limits_enabled` boolean — Whether to restrict this key to specific models. When `true`, only model IDs listed in `model_limits` are allowed. When `false`, `model_limits` is ignored.
  - `model_limits` string — Comma-separated model IDs allowed by this key when `model_limits_enabled` is `true`. Use model IDs returned by `/v1/models`, for example `<model-id-1>,<model-id-2>`. Use an empty string for no model restriction.
  - `allow_ips` string, nullable — Optional IP allowlist. Provide one JSON string with entries separated by newline characters (`\n`). Each entry can be a single IPv4 address, single IPv6 address, IPv4 CIDR, or IPv6 CIDR. Example for three allowlist entries: `198.51.100.10\n203.0.113.0/24\n2001:db8::/32`. CometAPI compares the model request client IP to this list. Use `null` or `""` to disable IP restrictions.
  - `group` string — Optional account group restriction. Use an empty string for no explicit group restriction. Non-empty values must be available to the account, or the API returns `success: false` with a `no access to group` message.
  - `cross_group_retry` boolean — Whether cross-group retry is enabled for automatic group routing. This is only meaningful when the key uses an auto-routed group such as `auto`.

## Response `200`

Create result.

- ResultEnvelope
  - `success` boolean, required — Whether the delete operation succeeded.
  - `message` string, required — Backend status message. The value is usually an empty string on success.

---

[API](https://skmtc.net/cometapi/apis/create-api-key.md) · [All operations](https://skmtc.net/cometapi/apis/create-api-key/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/cometapi/create-api-key/versions/0863102dbf34/schema)
