> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# `POST /v1/control/api-keys`.

> # Errors

`401`, `403`, `409` when the label is already in use by an active key, and
`503` when the store cannot be reached.



## OpenAPI

````yaml /openapi.json post /v1/control/api-keys
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers:
  - url: https://qa.esectra.com
    description: Esectra QA Documentation
security: []
paths:
  /v1/control/api-keys:
    post:
      tags:
        - Control
      summary: '`POST /v1/control/api-keys`.'
      description: >-
        # Errors


        `401`, `403`, `409` when the label is already in use by an active key,
        and

        `503` when the store cannot be reached.
      operationId: create_handler
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateApiKeyBody'
        required: true
      responses:
        '201':
          description: Created; carries the secret, once
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreatedApiKeyBody'
        '403':
          description: The reviewer does not hold API_KEY_MANAGE
        '409':
          description: An active key already has this label
        '422':
          description: The label is blank or too long
        '503':
          description: A backing store could not be reached
      security:
        - session_cookie: []
components:
  schemas:
    CreateApiKeyBody:
      type: object
      description: What a new key is for.
      required:
        - label
      properties:
        label:
          type: string
          description: >-
            A label. Required: it is the only thing distinguishing one key from

            another in the list, and an unlabelled key is one nobody dares
            revoke.
    CreatedApiKeyBody:
      type: object
      description: >-
        A newly created key, with its secret. The only response that carries
        one.
      required:
        - id
        - label
        - secret
      properties:
        id:
          type: string
          description: Identifier.
        label:
          type: string
          description: What it is for.
        secret:
          type: string
          description: >-
            The secret.


            Returned exactly once, by this call, and never again: only its hash
            is

            stored, so there is nothing for a later request to return. The
            console

            must tell the person that before they navigate away.
  securitySchemes:
    session_cookie:
      type: apiKey
      in: cookie
      name: esectra_session
      description: >-
        A signed-in reviewer's session. httpOnly and SameSite=Lax; set by `POST
        /v1/control/sessions` and only usable once the second factor is met.

````