v50

latestOpenAPI 3.0.0raw.githubusercontent.com2026-05-291317322.2 KB
API keys

Create new API Key

Creates a new pair of API Key and appToken.

Permissions

Any user or API key must have at least one of the appropriate License Manager resources to be able to successfully run this request. Otherwise they will receive a status code 403 error. These are the applicable resources for this endpoint:

ProductCategoryResource
License ManagerServices access controlSave user

You can create a custom role with that resource or use one of the following predefined roles:

RoleResource
User Administrator - RESTRICTEDSave user

❗ Assigning a predefined role to users or application keys usually grants permission to multiple License Manager resources. If some of these permissions are not necessary, consider creating a custom role instead. For more information regarding security, see Best practices for using application keys.

To learn more about machine authentication at VTEX, see Authentication overview.

post/api/vlm/appkeys

Request body

labelstring required

Label of the API key.

Example request

{
  "label": "apikey-test"
}

Response

Success

idstring required

ID of the API key.

appKeystring required

AppKey.

appTokenstring nullable required

AppToken. For security reasons, it should always be null.

labelstring required

Label of the API key.

createdInstring date-time required

Creation date of the API key.

isActiveboolean required

Defines if the API key is active (true) or not (false).