---
title: "Create API key"
method: POST
path: "/api-keys"
tags: ["API Keys"]
---

# Create API key

`POST /api-keys`

Create an API key. The secret is returned only once.

## Headers

- `X-Agent-ID` string, nullable
- `X-Instance-ID` string, nullable

## Request body

- object
  - `data` object, required
    - `attributes` object, required
      - `name` string, required — API key name.
      - `scopes` string[] — Permission scopes for the API key.

## Response `201`

Successful Response

- object
  - `data` object, required
    - `type` 'apiKey', required
    - `id` string, required — API key ID (apy_*).
    - `attributes` object, required
      - `apiKeyPrefix` string, required — Non-secret prefix of the API key, e.g. `sk_ntl_prod_abc123`.
      - `name` string, required — API key name.
      - `scopes` string[], required — Authorized scopes.
      - `environment` 'sandbox' | 'prod', required — Environment.
      - `status` 'ACTIVE' | 'REVOKED' | 'UNKNOWN', required — API key status.
      - `createdAt` string, date-time, required — When this key was created.
      - `lastUsedAt` string, date-time, nullable, required — When this key was last used.
      - `revokedAt` string, date-time, nullable, required — When this key was revoked.
      - `createdBy` string, nullable, required — User who created this key (usr_*).
      - `revokedBy` string, nullable, required — User who revoked this key (usr_*).
      - `apiKey` string, required — Full API key secret. Returned only once.
    - `relationships` object, required
      - `party` object, required — Party that owns the API key.
        - `data` object, required — Related resource identifier.
          - `type` 'party', required
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

---

[API](https://skmtc.net/natural/apis/natural-api.md) · [All operations](https://skmtc.net/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/natural/natural-api/versions/0bb9c54b1f61/schema)
