Create an API key
POST
/auth/api-keys
const url = 'https://api.krakenkey.io/auth/api-keys';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"name":"default","expiresAt":"2027-01-01T00:00:00.000Z","scopes":["certs:read","certs:renew","account:read"],"allowedDomainIds":["example"],"allowedCertIds":[1],"allowedIps":["203.0.113.10","2001:db8::/48"]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.krakenkey.io/auth/api-keys \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "name": "default", "expiresAt": "2027-01-01T00:00:00.000Z", "scopes": [ "certs:read", "certs:renew", "account:read" ], "allowedDomainIds": [ "example" ], "allowedCertIds": [ 1 ], "allowedIps": [ "203.0.113.10", "2001:db8::/48" ] }'Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
name
A human-friendly name for this API key
string
Example
my-ci-keyexpiresAt
ISO 8601 expiration date (optional, null = never expires)
string
Example
2027-01-01T00:00:00.000Zscopes
Scopes the key may use. Omit for full access. Cannot be changed after creation.
Array<string>
Example
[ "certs:read", "certs:renew", "account:read"]allowedDomainIds
Limit the key to these domain ids: certificates, domains and endpoints under other domains are hidden and new ones are refused.
Array<string>
allowedCertIds
Limit the key to these certificate ids. Such a key cannot request new certificates.
Array<number>
allowedIps
IP addresses or CIDR ranges (IPv4 or IPv6) the key may be used from. Requests from elsewhere get 403.
Array<string>
Example
[ "203.0.113.10", "2001:db8::/48"]Responses
Section titled “Responses”API key created
Unauthorized