Create a new scoped API key
Create an additional API key on the authenticated account, with its own name, scopes and compliance policy. Scopes narrow what a key may do — issue a key scoped to `extract` for an agent that should never be able to start a crawl. A key can only grant scopes the calling key already holds. The raw key is returned **once, in this response**, and is stored hashed; there is no way to read it back. Unmetered.
Authorization
BearerAuth Your API key, sent as Authorization: Bearer wm_.... Keys are wm_ followed by 40 hex characters. Create one with POST /register (free, no auth) or POST /keys.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/keys" \ -H "Content-Type: application/json" \ -d '{ "scopes": [ "string" ] }'{ "api_key": "string", "created_at": "2019-08-24T14:15:22Z", "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "name": "string", "scopes": [ "string" ]}List your API keys (metadata only — never the raw keys)
List every developer key on the authenticated account, including revoked ones — a non-null `revoked_at` marks a key as dead. Metadata only. Raw key values are stored hashed and are never returned by any endpoint; `key_prefix` is provided so you can match a row against a key you already hold. Unmetered.
Rotate the API key you're calling with (old key invalidated immediately)
Replace the key used to authenticate **this** request with a fresh one that inherits its name, scopes and policy. The old key is revoked immediately, so the call that rotates a key is the last call that key can make. Capture the new value from this response before issuing another request — it is shown once and stored hashed. Use this for routine rotation or after a suspected leak. To retire a *different* key, use `DELETE /keys/{key_id}`. Unmetered.