---
title: "Create API key"
method: POST
path: "/apps/{app_id}/auth/tokens"
---

# Create API key

`POST /apps/{app_id}/auth/tokens`

Use the OneSignal API to create a new Rich Authentication Token (App API Key) for a specific app. This guide explains how to authenticate with the Organization API key and configure optional IP allowlists using CIDR notation.

## Path parameters

- `app_id` string, required

## Headers

- `Content-Type` string, required
- `Authorization` string, required

## Request body

- object
  - `name` string, required — An internal name you set to help organize and track API keys (Rich Authentication Tokens). Maximum 128 characters.
  - `ip_allowlist_mode` 'disabled' | 'explicit' — Defaults to `disabled`, can be set to `explicit`. If set to `explicit`, a list of network addresses in the form of CIDRs has to be specified in the `ip_allowlist` parameter.
  - `ip_allowlist` string[] — An array of allowed networks in CIDRs notation. Only IPs in those ranges will be permitted to use the API key.

## Response `200`

The newly-created API key token. `token_id` and `formatted_token` are populated; `formatted_token` is the secret and is returned ONCE — store it now or rotate later.

- ApiKeyToken — An API Key Token record (Rich Authentication Token). Different operations return different subsets of these fields: - **GET tokens** lists every field except `formatted_token`. - **POST tokens** (create) returns `token_id` and `formatted_token`. - **POST tokens/{id}/rotate** returns `formatted_token` only. - **PATCH tokens/{id}** updates the record; the response body is currently empty (consumers should re-fetch via GET). `formatted_token` is the actual REST API Key and is shown ONCE — OneSignal does not store it. Keep it secret.
  - `token_id` string, uuid — OneSignal-generated identifier for this API key. NOT the API key itself — use this to manage the key in subsequent calls.
  - `name` string — Internal name set when the key was created or last updated. Maximum 128 characters.
  - `ip_allowlist_mode` 'disabled' | 'explicit' — When `explicit`, only requests from IP addresses matching `ip_allowlist` may use this key. Defaults to `disabled`.
  - `ip_allowlist` string[] — Allowed CIDR ranges. Only enforced when `ip_allowlist_mode` is `explicit`.
  - `created_at` string, date-time — ISO-8601 timestamp when the key was created.
  - `updated_at` string, date-time — ISO-8601 timestamp when the key was last updated.
  - `formatted_token` string — The actual Rich Authentication Token (REST API Key). Returned in plaintext ONLY by the create and rotate endpoints, and ONLY immediately after that call. OneSignal does not store the secret — if you lose it, you must rotate the key. See [Rotate API Key](/reference/rotate-api-key).

## Other responses

- `400` — 400
- `403` — Forbidden. Your organization permissions do not allow this action.
- `404` — App not found.
- `429` — Rate limit exceeded. Wait the number of seconds in the `Retry-After` header before retrying.
- `503` — Service temporarily unavailable. Retry after a short backoff. The body may be empty or non-JSON in some failure modes.

---

[API](https://skmtc.net/onesignal/apis/api-onesignal-com.md) · [All operations](https://skmtc.net/onesignal/apis/api-onesignal-com/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/onesignal/api-onesignal-com/versions/0fc223f7e338/schema)
