---
title: "Create endpoint access key"
method: POST
path: "/api/v1/objectstorageendpoints/{objectStorageEndpointID}/accesskeys"
tags: ["Object storage"]
---

# Create endpoint access key

`POST /api/v1/objectstorageendpoints/{objectStorageEndpointID}/accesskeys`

Creates an access key for the specified object storage endpoint. The server generates the immutable access key identifier and secret. The secret is returned only once in the create response.

## Request body

- ObjectStorageAccessKeyCreate — An object storage access key create request.
  - `metadata` ResourceMetadata, required — Metadata required for all API resource reads and writes.
    - `name` string, required — A valid Kubernetes label value, typically used for resource names that can be indexed in the database.
    - `description` string — The resource description, this optionally augments the name with more context.
    - `tags` Tag[] — A list of tags.
      - `name` string, required — A unique tag name.
      - `value` string, required — The value of the tag.
  - `spec` ObjectStorageAccessKeyCreateSpec, required — An object storage access key create specification.
    - `identityPolicy` string, required — The identity policy name associated with the access key.

## Response `201`

A newly created object storage access key. The generated secret is returned only once.

- ObjectStorageAccessKeyCreateResponseBody — An object storage access key create response.
  - `metadata` ProjectScopedResourceReadMetadata, required — Metadata required for all API resource reads and writes.
    - `name` string, required — A valid Kubernetes label value, typically used for resource names that can be indexed in the database.
    - `description` string — The resource description, this optionally augments the name with more context.
    - `tags` Tag[] — A list of tags.
      - `name` string, required — A unique tag name.
      - `value` string, required — The value of the tag.
    - `id` string, required — The unique resource ID.
    - `creationTime` string, date-time, required — The time the resource was created.
    - `createdBy` string — The user who created the resource.
    - `modifiedTime` string, date-time — The time a resource was updated.
    - `modifiedBy` string — The user who updated the resource.
    - `deletionTime` string, date-time — The time the resource was deleted.
    - `provisioningStatus` 'unknown' | 'provisioning' | 'provisioned' | 'deprovisioning' | 'error', required — The provisioning state of a resource.
    - `healthStatus` 'unknown' | 'healthy' | 'degraded' | 'error', required — The health state of a resource.
    - `organizationId` string, required — The organization identifier the resource belongs to.
    - `projectId` string, required — The project identifier the resource belongs to.
  - `spec` ObjectStorageAccessKeyCreateResponseSpec, required — An object storage access key create response specification.
    - `identityPolicy` string, required — The identity policy name associated with the access key.
    - `accessKeyId` string, required — The S3 access key identifier.
    - `secret` string, required — The generated secret for the access key. This value is returned only once when the access key is created.

## Other responses

- `400` — Request body failed schema validation, or the request does not contain all the required fields.
- `401` — Authentication failed or the access token has expired.
- `403` — Request was denied by authorization, this may be caused by the authorization token not having the required scope for an API, or the user doesn't have the necessary privileges on the provider platform.
- `404` — Unable to find a resource.
- `422` — The provided request was syntactically correct but the instruction was unable to be processed due to semantic errors.
- `500` — An unexpected or unhandled error occurred. This may be a transient error and may succeed on a retry. If this isn't the case, please report it as an issue.

---

[API](https://skmtc.net/nscale/apis/region-service-api.md) · [All operations](https://skmtc.net/nscale/apis/region-service-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/nscale/region-service-api/revisions/c2991b23da6e/schema)
