Create an API key
Mints a new self-service API key for the calling workspace. scopes must be a subset of the calling credential’s own scopes — a key can never mint another key with broader access than itself (a caller with unrestricted access, i.e. no scopes or *, may grant any scope, and an omitted scopes defaults to its own scopes). A new key cannot outlive a finite calling credential. Requires the calling credential to be a workspace owner/admin (service-account keys always qualify). The plaintext key is returned exactly once and cannot be retrieved again. Required scope: settings:write.
Authorizations
API key (fam_..., created under Settings → API Keys) or an OAuth 2.0 access token (fam_at_...). REST operations also require API Access for the credential's workspace. Keys can be restricted to scopes such as assistants:read, calls:write, campaigns:write, automations:read, dashboards:read, dashboards:write, leads:write, segments:write, loop:read, loop:write, phone_numbers:write, sip_trunks:write, knowledge:write, voices:read, billing:read, settings:write, platform:read, platform:write; a *:write scope implies the matching *:read. Automation and dashboard endpoints also accept the legacy calls:* scope. Keys without scope restrictions have full access within the workspace's available capabilities.
Body
100Must be a subset of the calling credential's own scopes — a key can never mint another key with broader access than itself. Omitted defaults to the calling credential's own scopes (or, if the credential itself has unrestricted access, every scope).
50Requested lifetime. Omitted inherits a finite calling credential's expiry, or means no expiry when the caller itself does not expire.
1 <= x <= 365Response
The minted key (shown once).
A newly-minted API key, including the plaintext secret.