---
title: "Create a new SSH Key"
method: POST
path: "/ssh-keys"
tags: ["SSH Keys"]
---

# Create a new SSH Key

`POST /ssh-keys`

Create a new SSH Key for a user. Provide the Public Key as formatted from the ssh-keygen command (openssh format or RFC-4716 format).

If you'd prefer to let us generate your key automatically, you can log in to your account via the web portal and set up new keys via the SSH Keys page.

## Headers

- `ev-api-key` string, required
- `ev-access-token` string, required

## Request body

- object
  - `userId` integer, required — ID of the user to assign the new key to.
  - `publicKey` string, required — Public Key to provide ExaVault. You can provide the Public Key as formatted from the ssh-keygen command or a standard rfc-4716 format.

## Response `200`

Successful Operation

- SSHKeyResponse
  - `responseStatus` integer — Http status code of the response.
  - `data` SSHKey — Object representing an SSH Key associated with a user.
    - `id` integer — ID of the key.
    - `type` 'sshKey' — Type of the object.
    - `attributes` SSHKeyAttributes
      - `fingerprint` string — The Key Fingerprint. The fingerprint can be used to identify and keep track of the key without exposing the actual credential.
      - `lastLogin` string, date-time — The date-time the SSH Key was last used to access ExaVault.
      - `created` string, date-time — The date-time the SSH Key was created.
    - `relationships` object
      - `ownerUser` object
        - `data` object
          - `id` integer
          - `type` string
  - `included` User[]
    - `id` integer — ID of the user.
    - `type` string — Type of object being returned. Always "user"
    - `attributes` UserAttributes — Attributes of the user including expiration, home directory, and permissions.
      - `status` 0 | 1, required — Indicates user activity status. `0` means the user is locked and cannot log in. `1` means the user is active and can log in.
      - `locked` boolean — `true` if the user is locked and cannot log in.
      - `expiration` string — Timestamp of user expiration.
      - `created` string, date-time, required — Timestamp of user creation.
      - `modified` string, date-time, required — Timestamp of user modification.
      - `accessTimestamp` string — Timestamp of most recent successful user login.
      - `accountName` string, required — Name of the account this user belongs to.
      - `username` string, required — Username of the user.
      - `nickname` string, required — Nickname of the user.
      - `email` string — Email address of the user.
      - `homePath` string — Path to the user's home folder.
      - `permissions` UserPermissions, required
        - `download` boolean, required — Download permission flag
        - `upload` boolean, required — Upload permission flag
        - `modify` boolean, required — Modify permission flag
        - `delete` boolean, required — Delete permission flag
        - `list` boolean, required — View folder contents permission flag
        - `changePassword` boolean, required — Change (own) password permission flag
        - `share` boolean, required — Sharing permission flag
        - `notification` boolean, required — Notifications permission flag
        - `viewFormData` boolean, required — Access Form Data permission flag. If true, user can view submissions that have been stored for a receive folder. This includes any data submitted in the receive folder form.
        - `deleteFormData` boolean, required — Delete form data permission flag. If true, user can remove data that was submitted for a receive folder. This applies only to data submitted in the receive folder form, not the actual files uploaded.
      - `role` 'user' | 'admin' | 'master', required — User's access level
      - `timeZone` string, required — User's timezone. See <a href='https://php.net/manual/en/timezones.php' target='blank'>this page</a> for allowed values.
      - `onboarding` boolean, required — Whether the onboarding help system is enabled for this user. `true` means that additional help popups are displayed in the web application for this user.
      - `firstLogin` boolean — `true` if the user has logged into the system.
    - `relationships` object — Home resource and owner account relationship data for the user.
      - `homeResource` object
        - `data` object
          - `type` 'resource' — Type is resource.
          - `id` integer — ID of home directory resource.
      - `ownerAccount` object, required
        - `data` object
          - `type` 'account' — Type is account.
          - `id` integer — ID of the account.

---

[API](https://skmtc.net/prismic/apis/exavault-api.md) · [All operations](https://skmtc.net/prismic/apis/exavault-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/prismic/exavault-api/revisions/a1bd874b5960/schema)
