# Create definitions key api-keys

Mints an API key for one record page and answers the plaintext secret ONCE, beside the key row — the service keeps only its hash, so a secret not saved now is gone. `name` is up to 80 characters and `scopes` must name at least one of read, rows:write, columns:write, partner, processing; the mint is attenuated at the admin's own ceiling, so a scope beyond it is refused. Workspace admin.

Access class: `def:admin`.

## Endpoint

`POST /v1/definitions/{key}/api-keys`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| key | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "name": "string",
    "scopes": [
      "string"
    ]
  },
  "params": {
    ":key": "string"
  },
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
