Skip to content
View as Markdown

Mint a new API key for a tenant.

POST/v1/abilities/key.issue

Mint a new API key for a tenant. Returns the raw key ONCE (only a sha256 is stored). Admin keys may issue for any tenant; a tenant key may issue only for its own tenant and never wider than itself (abilities/collections must be a subset). Auth-required.

Required
Yes
Content type
  • application/json
  • inputKeyIssueInputrequired
    Show 11 properties
    • tenantstringoptional

      Tenant id the key belongs to (^[a-z0-9][a-z0-9_-]{1,63}$). Default: the caller’s tenant.

    • namestringoptional

      Human label, e.g. “console”, “sebenza prod”. Default: the tenant.

    • abilitiesone of 2 variantsrequired

      “*” or an explicit list of ability ids. REQUIRED — a key with no stated scope is refused.

      Show 2 variants
      • string
        Allowed values: *
      • string[]
    • collectionsstring[]optional

      Memory collections this key may read/write (Qdrant). Default none.

    • allowSubTenantbooleanoptional

      May scope calls to <tenant>__<sub> (one key, many orgs). Default false.

    • personastringoptional

      Optional per-key voice for /agent (max 4000 chars).

    • componentsone of 2 variantsoptional

      gen-UI component scope: “*”, a tier (basic|pro|enterprise) or an explicit list.

      Show 2 variants
      • string
      • string[]
    • guideProductsstring[]optional

      Help-centre products this key may publish to.

    • simGeneratebooleanoptional

      May generate playable case studies.

    • adminbooleanoptional

      Mint an ADMIN key (manage keys for any tenant). Admin callers only.

    • expiresInDaysnumberoptional

      Optional expiry, 1..3650 days.

  • contextCallContextoptional

    Optional call context. The tenant always comes from the credential: tenantId is honoured only by a credential allowed to address sub-tenants, and then nests under the credential’s own tenant.

    Show 3 properties
    • tenantIdstringoptional

      Sub-tenant to act for (sub-tenant credentials only).

    • runIdstringoptional

      The trust run (from trust.preflight) this call executes under.

    • verticalIdstringoptional

      Vertical to attribute created records to.

Schema shown for 200 · application/json

  • result

    The ability’s return value. Its shape depends on the ability.