Keys
More ways to use this page
Create a key
POST/v1/
TypeScript sendora
Python sendora
Key sk_… a server key
Creates another live key for this server and answers its value once; it is never shown again. Every key of a server has the same rights. A server holds at most two live keys: the one in use and the one being rotated in.
Request body
namestring (at least 1, at most 100 characters)required1 to 100 characters.
{
"name": "Invoicing system"
}Responses
201The new key, its value shown this once.
tokenIdstring (uuid)requirednamestringrequiredThe name given at creation, for people to tell keys apart.
prefixstringrequiredThe first characters of the key, to match it with a value in hand.
createdAtstring (date-time)requiredrevokedAtstring (date-time) or nullrequiredtokenstringrequiredThe key itself, shown this once.
Example
{
"tokenId": "3b0c9e2f-6d4a-4e8b-8a1c-9f2d7e6c5b40",
"name": "Invoicing system",
"prefix": "sk_a1b2c3d4e5",
"createdAt": "2026-09-15T12:00:00.000Z",
"revokedAt": null,
"token": "sk_a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6q7r8s9t0u1v"
}Errors
Every error answers error, the code, and message, a sentence for a person. A code that adds fields is shown in full below the table.
| Code | Status | Meaning |
|---|---|---|
invalid_ | 400 | The body, the query or a header does not match what the route takes. |
unauthorized | 401 | The key is missing, malformed or revoked. |
wrong_ | 403 | The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes. |
token_ | 409 | The server or the account already holds two live keys: one in use and one to rotate to. Revoke one before creating another. |
invalid_request
issuesarray of objectOne entry per invalid field; absent when a header is wrong.
pathstringrequiredThe field, dotted, such as to.0.email; empty when the whole body is wrong.
messagestringrequired
Example
{
"error": "invalid_request",
"message": "The request is invalid: to.0: Invalid email address",
"issues": [
{
"path": "to.0",
"message": "Invalid email address"
}
]
}token_limit
maxintegerrequiredLive keys the owner may hold at once.
Example
{
"error": "token_limit",
"message": "The server may hold at most 2 live keys; revoke one before creating another.",
"max": 2
}