Create and reveal an API key for a merchant user.
POST
/api/api-keys/for-user
deprecated
Requires: ApiKeyAuthorization.ApiKeys.CreateForUser, merchant scope.
Mints an API key owned by the target merchant user and returns it with the revealed value. A reseller or admin authorized over the user's merchant may call this. Every authorization or existence failure returns an identical not-found response.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a CreateApiKeyForMerchantUserDto. See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
application/json
, required
| Field | Type | Description |
|---|---|---|
userId
required |
string (uuid) | The identity user the key is minted for (the owner). Must be an active merchant user of `merchantId` in the current tenant. |
merchantId
required |
string (uuid) | The merchant the target user belongs to, used for the server-side scope check. |
name
required |
string | Human-readable key name. nullablemax length 32 |
expireAt
required |
string (date-time) | Required expiry. A durable credential provisioned for another user must not be immortal, so a null value is rejected. nullable |
This request body has no documented fields.
Responses
200 OK
Body: ApiKeyRevealedDto
Each item has these fields.
| Field | Type | Description |
|---|---|---|
id
required |
string (uuid) | |
name
required |
string | Gets or sets the display name of the API key. nullable |
keyPrefix
required |
string | Gets or sets the leading characters of the key value, safe to display. `null` for a key the rewrap backfill has not reached. nullable |
last4
required |
string | Gets or sets the trailing characters of the key value, safe to display. `null` for a key the rewrap backfill has not reached. nullable |
environment
required |
all of ApiKeyEnvironment | Gets or sets which world the key acts in, or `null` when it has never been stamped. nullable |
status
required |
all of ApiKeyStatus | Gets or sets the key's administrative state. |
maskedKey
required |
string | Gets the key's display form: its retained prefix, an ellipsis, and its last characters. This is the only representation of the value any read path carries. nullableread only |
lastUsedAt
required |
string (date-time) | Gets or sets the UTC instant the key was last used to authenticate, or `null` when it has no recorded use. nullable |
creationTime
required |
string (date-time) | Gets or sets the UTC instant the key was created. |
merchantId
required |
string (uuid) | Gets or sets the merchant the key was minted for, or `null` when it is not tied to one. nullable |
active
required |
boolean | Gets or sets a value indicating whether the API key is active. |
expireAt
required |
string (date-time) | Gets or sets the expiration date for the API key. Null indicates the key does not expire. nullable |
userId
required |
string (uuid) | Gets or sets the user ID that owns this API key. |
replacesKeyId
required |
string (uuid) | Gets or sets the key this one was minted to replace, or `null` when it was not created by a rotation. nullable |
replacedByKeyId
required |
string (uuid) | Gets or sets the key minted to replace this one, or `null` when it has not been rotated. nullable |
overlapExpiresAt
required |
string (date-time) | Gets or sets when this key's rotation overlap closes and it stops authenticating, or `null` when it is not in one. nullable |
allowedCidrs
required |
array of string | Gets or sets the source addresses this key may be used from, as CIDR ranges or bare addresses, or `null` when it is not bound to any and may be used from anywhere. nullable |
scopes
required |
array of string | Gets or sets the capability scopes this key is restricted to, or `null` when it is unrestricted and may reach everything its owner can. nullable |
key
required |
string | Gets or sets the plaintext API key value. Shown once, at creation, and never again. nullable |
replacedKeyOverlapExpiresAt
required |
string (date-time) | Gets or sets when the key this one replaced stops authenticating, or `null` when this key was not created by a rotation, or was created by one that cut over immediately. nullable |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.