Issue a tenant API key
Creates an API key for a tenant and returns its token.
/v1/tenants/{tenantId}/api_keysCreates an API key for a tenant and returns its token. The token is
sk_{env}_{key-id}_{secret}; only an Argon2id hash of the secret is
stored, so the token is shown exactly once, here, and can never be
retrieved again. If it is lost, revoke the key and issue another.
Requires a staff token with a platform role (platform_ops or
global_admin); a tenant admin or support token is refused with
403 forbidden. Either an authsvc-minted staff token or, where SSO is
configured, a realm-signed one is accepted. The issuance is written to
audit_log in the same transaction as the key row, attributed to the
staff actor.
scopes is required and must be non-empty: the wildcard * has to be
asked for and is never defaulted. env defaults to sandbox. Keys are
issued with a one-year expiry so that rotation is planned work rather
than an outage.
Authorization
staffToken A portal staff session JWT (typ=staff), either minted by this service through POST /v1/auth/login or, where SSO is configured, issued by the configured identity realm. The operator endpoints additionally require a platform role (platform_ops or global_admin).
In: header
Path Parameters
The tenant's uuid.
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
application/problem+json
curl -X POST "https://example.com/v1/tenants/497f6eca-6276-4993-bfeb-53cbbbba6f08/api_keys" \ -H "Content-Type: application/json" \ -d '{ "env": "live", "name": "checkout-backend", "scopes": [ "users:write", "transfers:write", "balances:read" ] }'{ "id": "4a1f8e6b-2c3d-4e5f-9a8b-7c6d5e4f3a2b", "env": "live", "name": "checkout-backend", "scopes": [ "users:write", "transfers:write", "balances:read" ], "token": "sk_live_<32-hex-key-id>_<64-hex-secret>"}List a tenant's API keys
Lists every key that can act in the tenant, active and revoked, oldest first, and never their secrets — incident response needs to see what exists before deciding what dies.
Revoke a tenant API key
Ends a key immediately, so revoking a leaked credential does not require shell access to the pod.