Skip to content

Create an API key (the secret is returned exactly once)

  • Method: POST
  • Path: /v1/orgs/{org}/api-tokens
  • Operation ID: createApiToken
  • Tag: API keys

Send Authorization: Bearer <credential>. The credential is either an API key (vsk_…) created for an organization, or an OIDC access token obtained by signing in to VirtScale.

Name Type Required Description
org string (uuid) Yes The organization’s id.

Content type application/json, schema ApiTokenCreateRequest, required.

Field Type Required Enum Description
expires_at string (date-time), nullable No Optional expiry. Omit for a key that does not expire.
name string Yes A label, so the key is identifiable in a list later.
scopes array of string No Subset of [‘read’, ‘write’]. Defaults to read-only.
Field Type Required Enum Description
secret string Yes The plaintext key. Shown once and never retrievable again: only a hash is stored. Save it now.
token ApiTokenOut Yes
token.created_at string (date-time) Yes
token.expires_at string (date-time), nullable No
token.id string (uuid) Yes
token.last_used_at string (date-time), nullable No
token.name string Yes
token.revoked_at string (date-time), nullable No
token.scopes array of string Yes

Every error response is application/problem+json (schema Problem).

Status Meaning
400 The request is malformed or failed validation.
401 The credential is missing or invalid.
403 The credential does not have permission to perform this operation.
404 The resource does not exist.
default Any other status is possible; the code field identifies the error.
curl -X POST "https://api.virtscale.nl/v1/orgs/$ORG_ID/api-tokens" \
  -H "Authorization: Bearer $VIRTSCALE_API_KEY" \
  -H "Content-Type: application/json" \
  --data @body.json