create_api_key
Mint a run or sub API key from the calling account tp_ key. Requires kind=account on the caller and an active plan. Writes a key row and returns the secret once, plus id, name, prefix, namespaces, tools, expiresAt, opBudgetTotal, and wipeOnExpire. No quota spend and no email. Run keys default to a 24 hour TTL, wipeOnExpire true, and one auto-generated namespace. Use finish_run to wipe a run key early. The tools array is the stored ACL allow-list of per-operation names, not these merged MCP names. manage_kv action=put is allowed only when the list includes kvp_put (or the list is omitted, which allows every operation). Unknown names are dropped. Former name: keys_create.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| kind | Yes | run: temporary job key with its own namespace. sub: longer-lived scoped key. Required. Account keys cannot be minted here. | |
| name | No | Display name. Default run-key or sub-key when omitted. | |
| tools | No | ACL allow-list of per-operation names stored on the key. These are the names REST and metering already use. Examples: usage_get, usage_periods_list, budget_get, budget_estimate, billing_machine_pay, kvp_put, kvp_get, kvp_delete, kvp_list, memory_put, memory_get, memory_search, file_upload, files_list, files_types, file_get, file_delete, rag_note, rag_search, inspect_storage, run_finish, keys_create, keys_list, keys_revoke, support_contact, inbox_create, inbox_list, inbox_get, inbox_delete, inbox_messages_list, inbox_message_get, inbox_message_raw, inbox_attachment_get, inbox_webhook_create, inbox_webhook_list, inbox_webhook_delete, inbox_webhook_deliveries_list, inbox_audit_list, inbox_blocklist_list, inbox_blocklist_add, inbox_blocklist_delete, schedule_create, schedule_list, schedule_get, schedule_delete, schedule_runs_list. Merged MCP tools check the matching name per action (manage_kv action=put checks kvp_put, search_documents source=documents checks rag_search, search_documents source=memory checks memory_search, index_document kind=file checks file_upload, index_document kind=note checks rag_note). Omit to allow every operation. Names outside this list are dropped. | |
| opBudget | No | Maximum metered operations this key may spend. Omit for no per-key cap. Values of 0 or less mean no cap. | |
| namespaces | No | Namespace allow-list. Omit on a run key to bind one generated run_ namespace. Omit on a sub key to allow every namespace. | |
| ttlSeconds | No | Lifetime in seconds. Omit for the default: 24 hours on a run key, no expiry on a sub key. | |
| wipeOnExpire | No | When true, namespaces bound to the key are wiped at expiry. Default true for run keys and false for sub keys. |