Skip to main content
POST
Create an API key; the token is returned once (console session only). Body: label, role, scopes[], expires_at, site (optional website id to bind the key to)
A person signed in to the console creates keys; a key cannot create keys. Choose scopes from sites:read, sites:write, facts:read, facts:write. Pass site to bind the key to one website: a bound key sees only that website and cannot create or delete websites. The token (ni_live_...) is in this response and nowhere else; store it.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
label
string
required
role
enum<string>
Available options:
viewer,
admin
scopes
enum<string>[]
Available options:
sites:read,
sites:write,
facts:read,
facts:write
expires_at
string<date-time>
site
string

Optional website id to bind the key to

Response

The key, with the token shown once

key_id
string
label
string
role
enum<string>
Available options:
viewer,
admin
scopes
string[]
expires_at
string | null
last_used_at
string | null
created_at
string
token
string

ni_live_... shown once