Create an API key
POST/api/v1/api-keys
POST /api-keys
curl -X POST 'https://www.unitpost.com/api/v1/api-keys' \
-H 'Authorization: Bearer YOUR_API_KEY' \
-H 'User-Agent: my-app/1.0' \
-H 'Content-Type: application/json' \
-d '{
"name": "Production server",
"capabilities": [
"emails:send"
]
}'Response · 201
{
"object": "api_key",
"id": "id_123",
"name": "Example",
"prefix": "string",
"scope": "full",
"capabilities": [
"string"
],
"last_used_at": "2026-01-01T00:00:00.000Z",
"revoked_at": "2026-01-01T00:00:00.000Z",
"created_at": "2026-01-01T00:00:00.000Z",
"key": "string"
}Create an API key scoped to the capabilities you choose. The response includes the plaintext key exactly once — store it securely now, because it can never be retrieved again (only revoked). This endpoint is session-gated: it requires a dashboard session and cannot be called with a Bearer API key.
Request body3 fields
| Field | Type | Description |
|---|---|---|
namerequired | string | — |
scope | enumfull | sending | read_only | — |
capabilities | enum[] | — |
Response · 201 fields10 fields
| Field | Type | Description |
|---|---|---|
objectrequired | string | — |
idrequired | string | — |
namerequired | string | — |
prefixrequired | string | — |
scoperequired | enumfull | sending | read_only | — |
capabilitiesrequired | string[] | — |
last_used_atrequired | object | — |
revoked_atrequired | object | — |
created_atrequired | string | — |
keyrequired | string | The plaintext secret. Shown exactly once — store it now; it can never be retrieved again. |
201401403422