WalletD developers
API keys

Issue a tenant API key

Creates an API key for a tenant and returns its token.

POST/v1/tenants/{tenantId}/api_keys

Creates an API key for a tenant and returns its token. The token is sk_{env}_{key-id}_{secret}; only an Argon2id hash of the secret is stored, so the token is shown exactly once, here, and can never be retrieved again. If it is lost, revoke the key and issue another.

Requires a staff token with a platform role (platform_ops or global_admin); a tenant admin or support token is refused with 403 forbidden. Either an authsvc-minted staff token or, where SSO is configured, a realm-signed one is accepted. The issuance is written to audit_log in the same transaction as the key row, attributed to the staff actor.

scopes is required and must be non-empty: the wildcard * has to be asked for and is never defaulted. env defaults to sandbox. Keys are issued with a one-year expiry so that rotation is planned work rather than an outage.

Authorization

staffToken
AuthorizationBearer <token>

A portal staff session JWT (typ=staff), either minted by this service through POST /v1/auth/login or, where SSO is configured, issued by the configured identity realm. The operator endpoints additionally require a platform role (platform_ops or global_admin).

In: header

Path Parameters

tenantId*string

The tenant's uuid.

Formatuuid

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

application/problem+json

curl -X POST "https://example.com/v1/tenants/497f6eca-6276-4993-bfeb-53cbbbba6f08/api_keys" \  -H "Content-Type: application/json" \  -d '{    "env": "live",    "name": "checkout-backend",    "scopes": [      "users:write",      "transfers:write",      "balances:read"    ]  }'
{  "id": "4a1f8e6b-2c3d-4e5f-9a8b-7c6d5e4f3a2b",  "env": "live",  "name": "checkout-backend",  "scopes": [    "users:write",    "transfers:write",    "balances:read"  ],  "token": "sk_live_<32-hex-key-id>_<64-hex-secret>"}