> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an API key

> Create an API key and return its secret once. Send the secret as a Bearer token on the REST API or any Pomerado MCP. A key carries only permissions you hold now; without permissions it carries all of them except api_keys:manage, which a key needs to manage keys. It expires after 90 days unless expires_in_days says otherwise. With deliver "dashboard", nothing is created yet: the answer is a Dashboard link where the person creates the key and sees the secret, so it never reaches this client.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/api-keys
openapi: 3.1.0
info:
  title: Pomerado API
  version: '1'
  description: >-
    Run and build website tools, follow their jobs, and manage logins, API keys
    and webhooks. Authenticate with a Pomerado API key (pom_…), an MCP OAuth
    token or a Dashboard session as a Bearer token.
servers:
  - url: https://api.pomerado.ai
security: []
tags:
  - name: api_keys
    x-group: API keys
  - name: webhooks
    x-group: Webhooks
paths:
  /v1/api-keys:
    post:
      tags:
        - api_keys
      summary: Create an API key
      description: >-
        Create an API key and return its secret once. Send the secret as a
        Bearer token on the REST API or any Pomerado MCP. A key carries only
        permissions you hold now; without permissions it carries all of them
        except api_keys:manage, which a key needs to manage keys. It expires
        after 90 days unless expires_in_days says otherwise. With deliver
        "dashboard", nothing is created yet: the answer is a Dashboard link
        where the person creates the key and sees the secret, so it never
        reaches this client.
      operationId: api_keys.create
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - name
              properties:
                name:
                  type: string
                  description: 1 to 100 characters, without leading or trailing spaces
                  minLength: 1
                  maxLength: 100
                  examples:
                    - Nightly price check
                  pattern: ^\S(?:.*\S)?$
                permissions:
                  type: array
                  items:
                    type: string
                    enum:
                      - tools:read
                      - usage:read
                      - tools:build
                      - runs:create
                      - jobs:read
                      - jobs:cancel
                      - connections:read
                      - credentials:manage
                      - api_keys:manage
                  description: >-
                    Permissions the key carries, each one you hold now. Default:
                    every permission you hold except api_keys:manage
                  minItems: 1
                  examples:
                    - - tools:read
                      - runs:create
                      - jobs:read
                  maxItems: 16
                integration_id:
                  type: string
                  description: >-
                    Bind the key to one integration: it then runs only that
                    integration's tools, and carries only tools:read,
                    runs:create, jobs:read and jobs:cancel
                  examples:
                    - int_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190
                expires_in_days:
                  $ref: '#/components/schemas/Int'
                  description: Days until the key expires, 1 to 365 (default 90)
                  examples:
                    - 30
                  minimum: 1
                  maximum: 365
                deliver:
                  type: string
                  enum:
                    - dashboard
                  description: >-
                    Answer a Dashboard link instead of the secret, so the secret
                    never reaches this client
              additionalProperties: false
      responses:
        '200':
          description: 'With deliver dashboard: where to finish'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DashboardDelivery'
        '201':
          description: The new key and its one-time secret
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiKeyWithSecret'
        '400':
          description: invalid_request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: unauthorized, reauthentication_required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: permission_not_held, forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: not_found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: api_key_limit_reached
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '413':
          description: request_too_large
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: internal_error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: temporarily_unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearer: []
components:
  schemas:
    Int:
      type: integer
      description: an integer
    DashboardDelivery:
      type: object
      required:
        - dashboard_url
      properties:
        dashboard_url:
          type: string
          description: >-
            A signed-in Dashboard page where the person finishes this and sees
            the secret once
      additionalProperties: false
    ApiKeyWithSecret:
      type: object
      required:
        - id
        - name
        - permissions
        - integration_id
        - prefix
        - created_via
        - created_at
        - expires_at
        - last_used_at
        - secret
      properties:
        id:
          $ref: '#/components/schemas/api_key_id'
        name:
          type: string
          examples:
            - Nightly price check
        permissions:
          type: array
          items:
            type: string
            enum:
              - tools:read
              - usage:read
              - tools:build
              - runs:create
              - jobs:read
              - jobs:cancel
              - connections:read
              - credentials:manage
              - api_keys:manage
          examples:
            - - tools:read
              - runs:create
              - jobs:read
        integration_id:
          anyOf:
            - $ref: '#/components/schemas/integration_id'
            - type: 'null'
          description: The one integration the key is bound to, or null for an account key
        prefix:
          type: string
          description: The token's visible start, pom_ and 8 hex digits, to tell keys apart
          examples:
            - pom_0f8e2d1c
        created_via:
          type: string
          enum:
            - dashboard
            - api
            - mcp
          description: Where the key was created
        created_at:
          $ref: '#/components/schemas/Timestamp'
        expires_at:
          $ref: '#/components/schemas/Timestamp'
        last_used_at:
          anyOf:
            - $ref: '#/components/schemas/Timestamp'
            - type: 'null'
          description: When a request last used the key, or null if none has
        secret:
          type: string
          description: >-
            The key's secret, shown in this answer only. Send it as a Bearer
            token.
          examples:
            - >-
              pom_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190_example-secret-not-a-real-key-0000000000000
      additionalProperties: false
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - retryable
            - docs_url
          properties:
            code:
              type: string
            message:
              type: string
            retryable:
              type: boolean
            docs_url:
              type: string
            details:
              type: object
              required: []
              properties: {}
              additionalProperties:
                $id: /schemas/unknown
          additionalProperties: false
      additionalProperties: false
    api_key_id:
      type: string
      description: 'an API key ID: key_ and 32 lowercase hex digits'
      examples:
        - key_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190
    integration_id:
      type: string
      description: 'an integration ID: int_ and 32 lowercase hex digits'
      examples:
        - int_0f8e2d1c4b3a49e8a7f6e5d4c3b2a190
    Timestamp:
      type: string
      format: date-time
      description: An ISO 8601 timestamp in UTC
      examples:
        - '2026-10-05T18:30:00.000Z'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.