Create an API key and return its one-time secret token (shown only here). Requires a user credential (an Owner or Admin) or a PORTFOLIO-scope Api-Key. Select an organization with an Organization-Id to create an organization key (a portfolio Owner/Admin bearer, or a portfolio Api-Key, selecting a client org creates a client-scoped key); omit it to create a portfolio-wide key if you are a portfolio Owner or Admin bearer. Portfolio and client keys are capped: creating one past the cap returns 409.
Release date, as YYYY-MM-DD. Defaults to 2026-07-21.
Target organization id (Organization-Id selector). Omit to manage portfolio keys as a bearer. Required for a PORTFOLIO-scope Api-Key, which may only manage one client org's keys at a time.
Target connection id; resolves to its organization.
Platform entity id; resolves to a connection's organization.
Optional source to disambiguate an Entity-Id.
When the key should expire (RFC-3339 UTC with an explicit Z). Must be in the future. Omit for a key that does not expire.
Opaque unique identifier of the created key. Treat as opaque.
The secret API-key token. Shown ONCE, here, at creation; it cannot be retrieved later. Store it securely.
Successful Response
The request was invalid.
Authentication failed or was missing.
The credential is not permitted for this request.
The requested resource was not found.
The request conflicts with existing state.
The request failed validation.
A service this request depends on was unavailable. Retry the request.