Create an API key
POST
Creates an API key with the scopes you choose. Save the secret; it is shown only once.
Access: User session: workspace admin or owner. API keys aren't supported.
- A workspace can have at most 20 active keys.
- A key cannot exceed its creator's current role. Removing the member, password recovery or first email verification revokes their keys.
header
AuthorizationBearer <token>Send Authorization: Bearer <token>. A token is an API key (lb_live_…, scoped, for programs) or a session (lb_sess_…, from signup or login, for people). See Authentication above.
X-Org-ID?stringSessions only: act on this organization (you must be a member). Default: your first organization.
application/json- body
name*stringLength
length <= 64scopes*array<>What the key may do.
Items
1 <= itemsexpires_at?|Optional expiry.
Format
date-timeKey created
application/json- response
id*stringname*stringscopes*array<>created_at*stringFormat
date-timelast_used_at*|Format
date-timeexpires_at*|Format
date-timerevoked*booleankey*stringThe key. Shown once; store it now.
note*stringcurl -X POST 'https://layerbeat.com/v1/api-keys' \ -H 'Content-Type: application/json' \ -d '{ "name": "ci", "scopes": [ "vm:read", "vm:write" ]}'{ "id": "key_rs6goiwfde7kq3mzt5xv2nuhpa", "name": "ci", "scopes": [ "vm:read", "vm:write" ], "created_at": "2026-10-01T10:00:00Z", "last_used_at": null, "expires_at": null, "revoked": false, "key": "lb_live_5ydt2mw7q4k6bz3nhf8xvcjrpa.dGhpc2lzbm90YXJlYWxrZXk", "note": "Store this key now. It is shown only once."}