APIKeyCreateV5
Request body for creating a v5 scoped-permission API key. permissions must be non-empty and may only contain permissions the caller itself holds (privilege-escalation guard). legacy_all cannot be requested.
- nameType: stringrequired
- permissionsType: array of Permission 1… unique!enumrequired
- accountType: stringnullable
_id Ignored on
/v5/apikeys— the key is always issued on the caller's own account. - alwaysType: boolean
_retrievable Visibility of the plaintext key.
false(default) means the key is shown exactly once, on this create response.trueretains the plaintext and returns it on every subsequent read. Only valid together with a caller-suppliedkey— requesting it without one is a validation error, because Koard never retains the plaintext of a key it generated. - expiresType: stringFormat: date-timenullable
_at Optional expiry. Defaults to a long-lived expiry when omitted.
- keyType: stringnullable
Optional bring-your-own-key. When provided, this exact value becomes the account's API key (used verbatim in the
x-koard-apikeyheader) instead of one Koard generates. Must match the v5 key format. Only a salted hash is stored; the plaintext is echoed back on this response.

