{
"success": true,
"data": {
"rawKey": "<string>",
"rawSecretKey": "<string>",
"apiKey": {
"id": "<string>",
"name": "<string>",
"keyPrefix": "<string>",
"type": "platform",
"rateLimitTier": "free",
"scopes": [
"agents:read"
],
"status": "ACTIVE",
"createdAt": "2023-11-07T05:31:56Z",
"lastUsedAt": "2023-11-07T05:31:56Z",
"expiresAt": "2023-11-07T05:31:56Z"
}
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Generate a new API key + secret key pair
Creates a new API key. The raw key and secret are returned only once and cannot be retrieved later. Store them securely.
{
"success": true,
"data": {
"rawKey": "<string>",
"rawSecretKey": "<string>",
"apiKey": {
"id": "<string>",
"name": "<string>",
"keyPrefix": "<string>",
"type": "platform",
"rateLimitTier": "free",
"scopes": [
"agents:read"
],
"status": "ACTIVE",
"createdAt": "2023-11-07T05:31:56Z",
"lastUsedAt": "2023-11-07T05:31:56Z",
"expiresAt": "2023-11-07T05:31:56Z"
}
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Authorizations
User JWT access token issued by POST /api/auth/verify or POST /api/auth/social/verify. Routes that accept both auth modes declare api-key and bearer-jwt security schemes.
Headers
Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.
Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.
Body
OpenAPI schema CreateApiKeyDto.
Human-readable name for the API key
Key type: platform (standard), developer (external agent developers), internal (admin only)
platform, developer, internal Permission scopes. Defaults to all public, non-admin scopes if omitted. admin:* cannot be created through this API.
agents:read, agents:write, trades:read, trades:execute, bots:read, bots:write, marketplace:read, ai:chat, read:tokens, read:trades, read:strategies, write:strategies, read:wallet, write:wallet, read:agents, write:agents, read:ai, write:ai, read:earn, read:notifications, write:notifications, read:analytics, admin:* Expiration date for the key