Create an API key
POST /api-keys
Mint a key and read its token — once.
Body
namestringRequiredWhat the key is for, up to 255 characters. It appears in the dashboard and in audit records.
permissionstringfull_access(the default) reaches every endpoint.sending_accessmay only send.domain_idstringRestrict the key to one verified domain. Allowed only with
sending_access; afull_accesskey carrying it is refused.
Request
curl -X POST "https://api.rasket.com/api-keys" \
-H "Authorization: Bearer $RASKET_API_KEY" \
-H "User-Agent: acme-billing/1.0" \
-H "Content-Type: application/json" \
-d '{
"name": "billing worker",
"permission": "sending_access",
"domain_id": "d91a7b60-1a5f-4a2e-9d1b-0d9f2c7a1e34"
}'const response = await fetch("https://api.rasket.com/api-keys", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.RASKET_API_KEY}`,
"User-Agent": "acme-billing/1.0",
"Content-Type": "application/json",
},
body: JSON.stringify({
name: "billing worker",
permission: "sending_access",
domain_id: "d91a7b60-1a5f-4a2e-9d1b-0d9f2c7a1e34"
}),
});
const { id } = await response.json();import os
import requests
response = requests.post(
"https://api.rasket.com/api-keys",
headers={
"Authorization": f"Bearer {os.environ['RASKET_API_KEY']}",
"User-Agent": "acme-billing/1.0",
},
json={
"name": "billing worker",
"permission": "sending_access",
"domain_id": "d91a7b60-1a5f-4a2e-9d1b-0d9f2c7a1e34"
},
)
id = response.json()["id"]Response 201
{
"id": "a4d2f0c8-5b31-4e7a-9c62-8f0b1d4e6a75",
"token": "rk_7Hq2Lm9Pu8jzPde0IgxLd6GncfBAepfJBd0Kh8oOOL8dKLzdocJ"
}tokenis returned by this response and never again. Store it before you close the connection; we keep only its hash.- A key inherits the team it was created in. It cannot reach another team's data.