create_api_key
Create a new LastPing API key with custom scope and expiry. Admin access required; plaintext key is shown once only, so save it immediately in a secret manager. For tracing-only keys, use create_ingest_key instead.
Instructions
Requires an API key with the admin scope or higher. Create a new LastPing API key. The plaintext key is returned ONCE and cannot be retrieved again — store it immediately in a secret manager. Set expires_at for a short-lived key. To give an exporter a tracing key for one monitor, use create_ingest_key instead: it needs only a write key.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Label for the key, e.g. "github-actions". | |
| scope | No | What the new key may do. "read" is every GET; "write" is everything except managing API keys; "admin" is everything, key management included. Omit for "write", which is the right tier for a credential handed to a job or an agent: it can do the work and cannot mint itself a replacement. A key can never be given a HIGHER scope than the key that creates it; asking for one is refused and the refusal names the ceiling. "ingest" can only send pings and telemetry (traces, metrics, logs) and cannot call the REST API at all: use it for a key that lives in a dotfile or an exporter's config. This tool needs an admin key; with a write key, use create_ingest_key, which mints a tracing key bound to one monitor. | |
| check_id | No | Only with scope "ingest": binds the key to this one monitor (UUID from list_monitors), so it can send telemetry for that monitor and nothing else. Required for an exporter that cannot name its monitor, such as Codex. | |
| expires_at | No | Optional RFC 3339 expiry, e.g. "2026-12-31T00:00:00Z". Omit for a 90-day key, capped at the creating key's own expiry. A key can never be given a longer life than the key that creates it. |