Hoppa till innehållet

Create a key

POST/v1/tokens

TypeScript sendora.tokens.create({ name })

Python sendora.tokens.create(name=...)

Key sk_… a server key

Creates another live key for this server and answers its value once; it is never shown again. Every key of a server has the same rights. A server holds at most two live keys: the one in use and the one being rotated in.

Request body

  • namestring (at least 1, at most 100 characters)required

    1 to 100 characters.

{
  "name": "Invoicing system"
}

Responses

201The new key, its value shown this once.

  • tokenIdstring (uuid)required
  • namestringrequired

    The name given at creation, for people to tell keys apart.

  • prefixstringrequired

    The first characters of the key, to match it with a value in hand.

  • createdAtstring (date-time)required
  • revokedAtstring (date-time) or nullrequired
  • tokenstringrequired

    The key itself, shown this once.

Example

{
  "tokenId": "3b0c9e2f-6d4a-4e8b-8a1c-9f2d7e6c5b40",
  "name": "Invoicing system",
  "prefix": "sk_a1b2c3d4e5",
  "createdAt": "2026-09-15T12:00:00.000Z",
  "revokedAt": null,
  "token": "sk_a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v"
}

Errors

Every error answers error, the code, and message, a sentence for a person. A code that adds fields is shown in full below the table.

CodeStatusMeaning
invalid_request400The body, the query or a header does not match what the route takes.
unauthorized401The key is missing, malformed or revoked.
wrong_token_kind403The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes.
token_limit409The server or the account already holds two live keys: one in use and one to rotate to. Revoke one before creating another.

invalid_request

  • issuesarray of object

    One entry per invalid field; absent when a header is wrong.

    • pathstringrequired

      The field, dotted, such as to.0.email; empty when the whole body is wrong.

    • messagestringrequired

Example

{
  "error": "invalid_request",
  "message": "The request is invalid: to.0: Invalid email address",
  "issues": [
    {
      "path": "to.0",
      "message": "Invalid email address"
    }
  ]
}

token_limit

  • maxintegerrequired

    Live keys the owner may hold at once.

Example

{
  "error": "token_limit",
  "message": "The server may hold at most 2 live keys; revoke one before creating another.",
  "max": 2
}