Control
`POST /v1/control/api-keys`.
Errors
401, 403, 409 when the label is already in use by an active key, and
503 when the store cannot be reached.
POST
`POST /v1/control/api-keys`.
Authorizations
A signed-in reviewer's session. httpOnly and SameSite=Lax; set by POST /v1/control/sessions and only usable once the second factor is met.
Body
application/json
What a new key is for.
A label. Required: it is the only thing distinguishing one key from another in the list, and an unlabelled key is one nobody dares revoke.
Response
Created; carries the secret, once
A newly created key, with its secret. The only response that carries one.

