---
title: "Create an API key"
description: "Issues a new API key in this workspace. The key is shown only in this response, and only its hash is stored. `expiresAt` makes it stop working at a set time, useful for a contractor or a one-off script. An expired key stays in the list until you revoke it."
canonical: https://docs.rumoro.dev/api/api-keys/create-api-key
markdown: https://docs.rumoro.dev/api/api-keys/create-api-key.mdx
---

# Create an API key

`POST /v1/api-keys`

Issues a new API key in this workspace. The key is shown only in this response, and only its hash is stored. `expiresAt` makes it stop working at a set time, useful for a contractor or a one-off script. An expired key stays in the list until you revoke it.

## Body

| Field | Required | Description |
| --- | --- | --- |
| `name` |  | A name for the key. Defaults to "default". |
| `scope` |  | write can do everything. read is limited to GET. |
| `expiresAt` |  | Expiry time in ISO 8601 or epoch ms, later than now. Set it for keys you hand to a script or contractor. Omit it or send null and the key never expires. |

## Responses

| Status | Meaning |
| --- | --- |
| 201 | The created key, visible only now |
| 400 | expiresAt must be a future time |
| 401 | The API key is missing or not valid |

The [OpenAPI document](https://api.rumoro.dev/v1/openapi.json) has every schema. Rules shared by all endpoints are in [Conventions](https://docs.rumoro.dev/conventions.mdx).
