Issue a scoped merchant API key
Returns the asm_... secret exactly once with Cache-Control: no-store; replays of the same Idempotency-Key return metadata without the secret and an explanatory notice. Scopes come from the request body (e.g. offers:read, redemptions:capture, redemptions:release, vouchers:introspect).
/v1/merchants/{id}/api-keysAuthorizationBearer token (JWT) · headerrequiredClerk human owner session JWT; iss must equal the configured Clerk issuer and the identity must be a human (not agent) owner with a verified email.
AuthorizationOAuth2 access token · headerrequiredagentsub:owneridstringrequiredIdempotency-KeystringrequiredRequired only where this parameter is listed. Same payload/key recovers prior operation; secret replays omit plaintext.
application/jsonnamestringscopesstring[]requiredKey issued (secret shown once)
apiKeystringThe asm_... secret; absent on replay
metadataMerchantKeyMetadataShow propertiesHide properties
keyIdstringmerchantIdstringownerIdstringnamestringscopesstring[]createdAtintegerrevokedAtintegernoticestringinvalid_input problem
typestringrequiredtitlestringrequiredstatusintegerrequiredcodestringrequiredunauthorized problem; live 401s advertise WWW-Authenticate: Bearer resource_metadata=...
typestringrequiredtitlestringrequiredstatusintegerrequiredcodestringrequiredIdentity, ownership, scope or policy denied (human_required, owner_claim_required, scope_required, FROZEN, CAP_EXCEEDED, SCOPE_FORBIDDEN)
typestringrequiredtitlestringrequiredstatusintegerrequiredcodestringrequiredRuntime or provider configuration unavailable (runtime_configuration_required, signing_configuration_required, runtime_unavailable, workspace_unavailable, provider_configuration_required)
typestringrequiredtitlestringrequiredstatusintegerrequiredcodestringrequired