APIKeyCreateV5

Request body for creating a v5 scoped-permission API key. permissions must be non-empty and may only contain permissions the caller itself holds (privilege-escalation guard). legacy_all cannot be requested.

  • Ignored on /v5/apikeys — the key is always issued on the caller's own account.

  • Visibility of the plaintext key. false (default) means the key is shown exactly once, on this create response. true retains the plaintext and returns it on every subsequent read. Only valid together with a caller-supplied key — requesting it without one is a validation error, because Koard never retains the plaintext of a key it generated.

  • Optional expiry. Defaults to a long-lived expiry when omitted.

  • Optional bring-your-own-key. When provided, this exact value becomes the account's API key (used verbatim in the x-koard-apikey header) instead of one Koard generates. Must match the v5 key format. Only a salted hash is stored; the plaintext is echoed back on this response.