Skip to main content
POST
Issue a new API key

Authorizations

Authorization
string
header
default:sk_test_DEMO0000_replace_with_your_sandbox_key
required

API key authentication. Issued by the Safariat admin or via the partner portal. The secret is shown only once at generation.

Production sk_live_* keys must additionally sign every write request (POST/PUT/DELETE) with the X-Timestamp and X-Signature headers. Sandbox sk_test_* keys are exempt from request signing: X-Signature and X-Timestamp are not required for writes in the sandbox (so the developer-portal "Try it" playground works end to end). The Idempotency-Key header remains required on writes in both environments.

Headers

Idempotency-Key
string
required

Opaque, client-generated string unique per logical operation (a UUID v4 is recommended but any non-blank value up to 255 chars is accepted). Same key + same body = the cached response is returned with the Idempotent-Replayed: true header. Same key + different body = 409 Conflict. Retained for 24 h.

Maximum string length: 255

Body

application/json
environment
enum<string>
required
Available options:
TEST,
LIVE
scopes
string[]
required
expires_at
string<date-time> | null

Response

Key created, bearer returned once.

id
string<uuid>
prefix
string
environment
enum<string>
Available options:
TEST,
LIVE
bearer_token
string

One-time clear-text bearer to store immediately in your secret manager. Safariat keeps only an argon2id hash and cannot retrieve this value again.

warning
string