v1

latestOpenAPI 3.1.02026-07-26497885.9 KB

Create API key

Use the OneSignal API to create a new Rich Authentication Token (App API Key) for a specific app. This guide explains how to authenticate with the Organization API key and configure optional IP allowlists using CIDR notation.

post/apps/{app_id}/auth/tokens

Path parameters

app_idstring required

Your OneSignal App ID in UUID v4 format. See Keys & IDs.

Headers

Content-Typestring required
Authorizationstring required

Your Organization API key with prefix Key . See Keys & IDs.

Request body

namestring required

An internal name you set to help organize and track API keys (Rich Authentication Tokens). Maximum 128 characters.

ip_allowlist_mode'disabled' | 'explicit'

Defaults to disabled, can be set to explicit. If set to explicit, a list of network addresses in the form of CIDRs has to be specified in the ip_allowlist parameter.

ip_allowliststring[]

An array of allowed networks in CIDRs notation. Only IPs in those ranges will be permitted to use the API key.

Response

The newly-created API key token. token_id and formatted_token are populated; formatted_token is the secret and is returned ONCE — store it now or rotate later.

token_idstring uuid

OneSignal-generated identifier for this API key. NOT the API key itself — use this to manage the key in subsequent calls.

namestring

Internal name set when the key was created or last updated. Maximum 128 characters.

ip_allowlist_mode'disabled' | 'explicit'

When explicit, only requests from IP addresses matching ip_allowlist may use this key. Defaults to disabled.

ip_allowliststring[]

Allowed CIDR ranges. Only enforced when ip_allowlist_mode is explicit.

created_atstring date-time

ISO-8601 timestamp when the key was created.

updated_atstring date-time

ISO-8601 timestamp when the key was last updated.

formatted_tokenstring

The actual Rich Authentication Token (REST API Key). Returned in plaintext ONLY by the create and rotate endpoints, and ONLY immediately after that call. OneSignal does not store the secret — if you lose it, you must rotate the key. See Rotate API Key.