Skip to content

Create an API key

POST
/auth/api-keys
curl --request POST \
--url https://api.krakenkey.io/auth/api-keys \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "name": "default", "expiresAt": "2027-01-01T00:00:00.000Z", "scopes": [ "certs:read", "certs:renew", "account:read" ], "allowedDomainIds": [ "example" ], "allowedCertIds": [ 1 ], "allowedIps": [ "203.0.113.10", "2001:db8::/48" ] }'
Media typeapplication/json
object
name

A human-friendly name for this API key

string
default: default
Example
my-ci-key
expiresAt

ISO 8601 expiration date (optional, null = never expires)

string
Example
2027-01-01T00:00:00.000Z
scopes

Scopes the key may use. Omit for full access. Cannot be changed after creation.

Array<string>
Allowed values: certs:read certs:issue certs:renew certs:revoke domains:read domains:write endpoints:read endpoints:write probes:report account:read account:write
Example
[
"certs:read",
"certs:renew",
"account:read"
]
allowedDomainIds

Limit the key to these domain ids: certificates, domains and endpoints under other domains are hidden and new ones are refused.

Array<string>
<= 50 items
allowedCertIds

Limit the key to these certificate ids. Such a key cannot request new certificates.

Array<number>
<= 50 items
allowedIps

IP addresses or CIDR ranges (IPv4 or IPv6) the key may be used from. Requests from elsewhere get 403.

Array<string>
<= 20 items
Example
[
"203.0.113.10",
"2001:db8::/48"
]

API key created

Unauthorized