---
title: "POST /v1/{+parent}/keys"
method: POST
path: "/v1/{+parent}/keys"
tags: ["organizations"]
---

# POST /v1/{+parent}/keys

`POST /v1/{+parent}/keys`

Creates a custom consumer key and secret for a AppGroup app. This is particularly useful if you want to migrate existing consumer keys and secrets to Apigee from another system. Consumer keys and secrets can contain letters, numbers, underscores, and hyphens. No other special characters are allowed. To avoid service disruptions, a consumer key and secret should not exceed 2 KBs each. **Note**: When creating the consumer key and secret, an association to API products will not be made. Therefore, you should not specify the associated API products in your request. Instead, use the UpdateAppGroupAppKey API to make the association after the consumer key and secret are created. If a consumer key and secret already exist, you can keep them or delete them using the DeleteAppGroupAppKey API.

## Path parameters

- `parent` string, required

## Request body

- GoogleCloudApigeeV1AppGroupAppKey — AppGroupAppKey contains all the information associated with the credentials.
  - `scopes` string[] — Scopes to apply to the app. The specified scope names must already be defined for the API product that you associate with the app.
  - `status` string — Status of the credential. Valid values include `approved` or `revoked`.
  - `consumerKey` string — Immutable. Consumer key.
  - `consumerSecret` string — Secret key.
  - `attributes` GoogleCloudApigeeV1Attribute[] — List of attributes associated with the credential.
    - `name` string — API key of the attribute.
    - `value` string — Value of the attribute.
  - `apiProducts` GoogleCloudApigeeV1APIProductAssociation[] — Output only. List of API products and its status for which the credential can be used. **Note**: Use UpdateAppGroupAppKeyApiProductRequest API to make the association after the consumer key and secret are created.
    - `status` string — The API product credential associated status. Valid values are `approved` or `revoked`.
    - `apiproduct` string — API product to be associated with the credential.
  - `issuedAt` string, int64 — Output only. Time the AppGroup app was created in milliseconds since epoch.
  - `expiresInSeconds` string, int64 — Immutable. Expiration time, in seconds, for the consumer key. If not set or left to the default value of `-1`, the API key never expires. The expiration time can't be updated after it is set.
  - `expiresAt` string, int64 — Output only. Time the AppGroup app expires in milliseconds since epoch.

## Response `200`

Successful response

---

[API](https://skmtc.net/google/apis/apigee.md) · [All operations](https://skmtc.net/google/apis/apigee/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/google/apigee/versions/6e272fa448a7/schema)
