Administration

api_keys.create

Create a scoped expiring API key within your current role and credential ceiling. The secret is returned once.

POST/api/v1/accounting/api_keys.create

Permissions

api_keys:manage

Who can call it

admin, finance, contributor

Retries

Idempotency key required

MCP

accounting_api_keys_create

Fields

  • namestringRequired

    A display name.

    1–100 characters · Matches ^[^\u0000-\u001f\u007f]+$

  • scopesarray of enum valuesRequired

    What the API key may do. A key can never do more than the person who made it.

    accounting:readaccounting:writeaccounting:adminmail:readmail:writemail:securityapi_keys:managemailboxes:search

    1–8 items

  • expiresAtstring (date-time)

    When this stops working, as an ISO 8601 date and time.

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–160 characters

Example

curl https://app.getoatmilk.com/api/v1/accounting/api_keys.create \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "name": "name",
  "scopes": [
    "accounting:read"
  ]
}'
Response
{
  "data": { … }
}

Try it

Try it

Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.

POST/api/v1/accounting/api_keys.create
curl https://app.getoatmilk.com/api/v1/accounting/api_keys.create \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "name": "name",
  "scopes": [
    "accounting:read"
  ]
}'

More in Administration.