Skip to content
POST
/v1/organizations/{organizationId}/projects/{projectId}/environments/{environmentId}/service-principals/{principalId}/api-keys

Issue an API Key for an Environment-scoped ServicePrincipal

Issue one named expiring credential and return its secret once. An identical committed retry returns only safe metadata; different input under the same Idempotency-Key returns Conflict.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

NameLocationRequiredDescription
organizationIdpathYes
The Organization to address.
stringA Cantora Organization identifier, prefixed with `org_`.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdpathYes
The Project to address.
stringA Cantora Project identifier, prefixed with `proj_`.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdpathYes
The Environment to address.
stringA Cantora Environment identifier, prefixed with `env_`.
  • maximum length 64
  • pattern ^env_[\s\S]+$
principalIdpathYes
The Principal to address.
stringA Cantora Principal identifier, prefixed with `principal_`.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
idempotency-keyheaderYes
The caller-chosen key that makes supported creation and issuance requests safe to retry; use 1–200 visible ASCII characters.

Request body

Required.

Responses

201ServicePrincipalApiKeyIssuance
400The request path, headers, query, or JSON body did not satisfy the published schema
401Unauthorized
application/json
403Forbidden
application/json
404NotFound
application/json
409Conflict
application/json

Reusable schemas

IdempotencyKey

stringA caller-chosen key of 1–200 visible ASCII characters that makes an identical request safe to retry.
  • maximum length 200
  • minimum length 1
  • pattern ^[!-~]+$

ServicePrincipalApiKeyIssuance

UnauthorizedEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.

NotFoundEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "NotFound"
resourcerequired
stringThe resource type relevant to the error.
idrequired
stringThe identifier supplied for the resource that was not found.

ConflictEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Conflict"
resourcerequired
stringThe resource type relevant to the error.
reasonrequired
stringA safe explanation of the state conflict.

ServicePrincipalApiKeyIssueRequest

object
  • unknown properties allowed false
namerequired
stringThe human-readable resource name.
expiresAtrequired
stringWhen the resource expires, in UTC, or null when it does not expire.
  • format date-time

IssuedServicePrincipalApiKeyEncoded

object
  • unknown properties allowed false
outcomerequired
stringWhether this request issued a credential or reconciled a previously committed issuance.
  • allowed values "issued"
credentialrequired
ApiKeyMetadataEncodedThe safe metadata for the newly issued credential.
apiKeyrequired
stringThe complete credential secret, returned exactly once.

ReusedServicePrincipalApiKeyEncoded

object
  • unknown properties allowed false
outcomerequired
stringWhether this request issued a credential or reconciled a previously committed issuance.
  • allowed values "reused"
credentialrequired
ApiKeyMetadataEncodedThe safe metadata for the previously committed credential.

ApiKeyMetadataEncoded

object
  • unknown properties allowed false
apiKeyIdrequired
stringThe identifier of the issued API key.
  • maximum length 64
  • pattern ^apikey_[\s\S]+$
principalIdrequired
stringThe Principal identifier.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
creationIdempotencyKeyrequired
The caller-chosen issuance key that identifies this committed credential.
Any of
null
namerequired
stringThe human-readable resource name.
displayPrefixrequired
stringThe non-secret leading characters used to distinguish this credential.
createdByPrincipalIdrequired
stringThe Principal that created this immutable record.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
createdAtrequired
stringWhen the resource was created, in UTC.
  • format date-time
expiresAtrequired
stringWhen the resource expires, in UTC, or null when it does not expire.
  • format date-time
lastUsedAtrequired
Approximately when this credential was last presented, in UTC, or null before its first use.
  • format date-time
Any of
string
null
revokedAtrequired
When the resource was revoked, in UTC, or null while it remains active.
  • format date-time
Any of
string
null
revokedByPrincipalIdrequired
The Principal that revoked this resource, or null while it remains active.
Any of
stringA Cantora Principal identifier, prefixed with `principal_`.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
null