API reference
Create an API key
Creates a scoped credential and returns its secret once.
POST /v1/api-keys
Request body
JSON body: PublicCreateApiKeyRequest
curl --request POST "https://yep.com/api/v1/api-keys" \
--header "Authorization: Bearer $YEP_API_KEY" \
--header "Content-Type: application/json" \
--data-binary @- <<'JSON'
{
"name": "string",
"permissions": [
"search-read"
]
}
JSON Responses
- Status
- 201
- Description
- Key created; the secret is present only in this response.
- Body
- PublicCreatedApiKey
- Status
- 400
- Description
- Invalid request.
- Body
- PublicApiError
- Status
- 401
- Description
- Authentication required.
- Body
- PublicApiError
- Status
- 403
- Description
- Requested permissions exceed current authority.
- Body
- PublicApiError
- Status
- 409
- Description
- The account is unavailable or its active-key quota is exhausted.
- Body
- PublicApiError
Schemas
ErrorCode
Machine-readable product API failure.
[
"unauthenticated",
"forbidden",
"invalid_request",
"not_found",
"conflict",
"payment_required",
"too_many_requests",
"upstream",
"internal"
] ErrorRecovery
Browser-safe recovery action selected by the authoritative product boundary.
- Variant
- 1
- Type
- object
- Variant
- 2
- Type
- object
- Variant
- 3
- Type
- object
PublicApiError
Stable public error envelope for APIs whose reason vocabulary is extensible.
- Field
- agent_session_id
- Required
- No
- Type
- string | null
- Description
- Agent execution correlation id, present after an invocation is admitted.
- Constraints
- Field
- code
- Required
- Yes
- Type
- ErrorCode
- Description
- Closed status category suitable for program control flow.
- Constraints
- Field
- message
- Required
- Yes
- Type
- string
- Description
- Safe diagnostic intended for operators, not program branching.
- Constraints
- Field
- reason
- Required
- Yes
- Type
- string
- Description
- Extensible machine-readable detail; clients must accept unknown values.
- Constraints
- Field
- recovery
- Required
- No
- Type
- null | ErrorRecovery
- Description
- Constraints
- Field
- validation
- Required
- No
- Type
- null | ValidationReport
- Description
- Constraints
PublicApiKeyPermission
Stable permission names accepted by the public API-key endpoint.
[
"search-read",
"agent-run",
"keys-create-own",
"keys-manage-own"
] PublicCreateApiKeyRequest
Stable public input for issuing a user-owned API key.
- Field
- expires_in_days
- Required
- No
- Type
- integer | null
- Description
- Requested lifetime in days; omission selects 90 days.
- Constraints
- default: 90; min: 1; max: 365
- Field
- monthly_spend_limit_microusd
- Required
- No
- Type
- integer | null
- Description
- Optional positive monthly spend ceiling in millionths of a US dollar.
- Constraints
- min: 1
- Field
- name
- Required
- Yes
- Type
- string
- Description
- Human-readable key name.
- Constraints
- min length: 1; max length: 100
- Field
- permissions
- Required
- Yes
- Type
- PublicApiKeyPermission[]
- Description
- Nonempty grants bounded by the caller's current effective permissions.
- Constraints
- min items: 1
PublicCreatedApiKey
Public metadata for a newly issued API key.
- Field
- created_at
- Required
- Yes
- Type
- string
- Description
- Creation timestamp in UTC.
- Constraints
- Field
- display_prefix
- Required
- Yes
- Type
- string
- Description
- Non-secret prefix used to identify the key.
- Constraints
- Field
- expires_at
- Required
- Yes
- Type
- string
- Description
- Mandatory expiry timestamp in UTC.
- Constraints
- Field
- id
- Required
- Yes
- Type
- string
- Description
- Stable credential id used for revocation.
- Constraints
- Field
- name
- Required
- Yes
- Type
- string
- Description
- User-provided display name.
- Constraints
- Field
- secret
- Required
- Yes
- Type
- string
- Description
- Plaintext secret present only in the creation response.
- Constraints
ValidationIssue
One actionable, privacy-safe contract violation.
- Field
- allowed_values
- Required
- No
- Type
- array | null
- Description
- Constraints
- max items: 16
- Field
- code
- Required
- Yes
- Type
- string
- Description
- Stable, extensible machine-readable category.
- Constraints
- max length: 64
- Field
- path
- Required
- Yes
- Type
- string
- Description
- RFC 6901 pointer to the rejected location; empty means the root value.
- Constraints
- max length: 1024
- Field
- suggestion
- Required
- Yes
- Type
- string
- Description
- Code-owned instruction for correcting the request.
- Constraints
- max length: 512
ValidationReport
Bounded validation feedback shared by model, REST, and MCP boundaries.
- Field
- contract
- Required
- Yes
- Type
- string
- Description
- Stable contract name, normally the published schema component name.
- Constraints
- max length: 128
- Field
- issues
- Required
- Yes
- Type
- ValidationIssue[]
- Description
- At most eight deterministic violations. Correct every issue before retrying.
- Constraints
- max items: 8
- Field
- truncated
- Required
- Yes
- Type
- boolean
- Description
- Whether more violations were omitted; retry after correcting the listed issues.
- Constraints