# api_keys.create

Create a scoped expiring API key within your current role and credential ceiling. The secret is returned once.

`POST /api/v1/accounting/api_keys.create`

Permissions: `api_keys:manage` · Roles: admin, finance, contributor · Idempotency key required

MCP tool: `accounting_api_keys_create`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `name` | string | Yes | A display name. 1–100 characters; Matches ^[^\u0000-\u001f\u007f]+$. |
| `scopes` | array of enum values | Yes | What the API key may do. A key can never do more than the person who made it. One of: `accounting:read`, `accounting:write`, `accounting:admin`, `mail:read`, `mail:write`, `mail:security`, `api_keys:manage`, `mailboxes:search`. 1–8 items. |
| `expiresAt` | string (date-time) |  | When this stops working, as an ISO 8601 date and time. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–160 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/api_keys.create \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "name": "name",
  "scopes": [
    "accounting:read"
  ]
}'
```

Reference page: https://app.getoatmilk.com/docs/api/api_keys.create
