Aller au contenu
agentsub
Esc
↑↓naviguer↵ouvrir⌘Japerçu

Issue a scoped merchant API key

Returns the asm_... secret exactly once with Cache-Control: no-store; replays of the same Idempotency-Key return metadata without the secret and an explanatory notice. Scopes come from the request body (e.g. offers:read, redemptions:capture, redemptions:release, vouchers:introspect).

POST/v1/merchants/{id}/api-keys
Authorization
AuthorizationBearer token (JWT) · headerrequired

Clerk human owner session JWT; iss must equal the configured Clerk issuer and the identity must be a human (not agent) owner with a verified email.

or
AuthorizationOAuth2 access token · headerrequired
Scopes:agentsub:owner
Path parameters
idstringrequired
Header parameters
Idempotency-Keystringrequired

Required only where this parameter is listed. Same payload/key recovers prior operation; secret replays omit plaintext.

matches ^[A-Za-z0-9._:-]{1,200}$
Request body
requiredapplication/json
namestring
scopesstring[]required
Responses
201

Key issued (secret shown once)

apiKeystring

The asm_... secret; absent on replay

metadataMerchantKeyMetadata
Show properties
keyIdstring
merchantIdstring
ownerIdstring
namestring
scopesstring[]
createdAtinteger
revokedAtinteger
noticestring
400

invalid_input problem

typestringrequired
titlestringrequired
statusintegerrequired
codestringrequired
401

unauthorized problem; live 401s advertise WWW-Authenticate: Bearer resource_metadata=...

typestringrequired
titlestringrequired
statusintegerrequired
codestringrequired
403

Identity, ownership, scope or policy denied (human_required, owner_claim_required, scope_required, FROZEN, CAP_EXCEEDED, SCOPE_FORBIDDEN)

typestringrequired
titlestringrequired
statusintegerrequired
codestringrequired
503

Runtime or provider configuration unavailable (runtime_configuration_required, signing_configuration_required, runtime_unavailable, workspace_unavailable, provider_configuration_required)

typestringrequired
titlestringrequired
statusintegerrequired
codestringrequired
Request
curl -X POST 'https://api.agentsub.dev/v1/merchants/string/api-keys' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Idempotency-Key: string' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "scopes": [
    "offers:read"
  ]
}'
Response
{
  "apiKey": "string",
  "metadata": {
    "keyId": "string",
    "merchantId": "string",
    "ownerId": "string",
    "name": "string",
    "scopes": [
      "string"
    ],
    "createdAt": 0,
    "revokedAt": 0
  },
  "notice": "string"
}