Skip to main content
POST
Create API key

Authorizations

sb-access-token
string
cookie
required

The signed-in browser session (Google or Apple). Used only for key management, same-origin JSON requests only. An API key presented here is refused (401 session_required).

Body

application/json
label
string

Trimmed; an empty label becomes "Untitled key".

Maximum string length: 64
scopes
enum<string>[]

Defaults to records:read, portfolio:read and markets:read. trade:write is reserved and refused (403 scope_not_available).

Minimum array length: 1
Available options:
records:read,
portfolio:read,
markets:read,
trade:write
expiresInDays
integer

Omit for a key that never expires.

Required range: 1 <= x <= 365

Response

Created.

key
object
required
token
string
required

The plaintext key. Shown once; only its hash is stored.

warning
string
required