Skip to main content
POST
`POST /v1/control/api-keys`.

Authorizations

esectra_session
string
cookie
required

A signed-in reviewer's session. httpOnly and SameSite=Lax; set by POST /v1/control/sessions and only usable once the second factor is met.

Body

application/json

What a new key is for.

label
string
required

A label. Required: it is the only thing distinguishing one key from another in the list, and an unlabelled key is one nobody dares revoke.

Response

Created; carries the secret, once

A newly created key, with its secret. The only response that carries one.

id
string
required

Identifier.

label
string
required

What it is for.

secret
string
required

The secret.

Returned exactly once, by this call, and never again: only its hash is stored, so there is nothing for a later request to return. The console must tell the person that before they navigate away.