Smart Capital Center API reference

createApiKey

POST
/api/v2/public/api-keys

Creates a named API key for the signed-in user. The key goes in the X-API-KEY header on every other call.

Auth: Authorization: Bearer <access_token> (or X-API-KEY)

Use when: Right after register or login, or when the user wants a separate key for a new integration.

Don't use when: A working key already exists for this integration. Check with getUserApiKeys first.

Request body

Content type: application/json

Field Type Required Description
name string yes Name of the API key. Max 100 chars. Example: My Application API Key.
description string no Description of the API key's purpose. Max 500 chars. Example: Used by the valuation integration.
expiresInDays integer no Number of days until the API key expires (null for no expiration). Example: 365.

Notes for agents

  • Send the bearer token from register or login in the Authorization header.
  • Omit expiresInDays for a key that never expires. Prefer an expiry when the user hasn't said otherwise, and tell them what you chose.
  • data.keyValue is returned only once. Show it to the user once, then mask it (sq_****) in anything you write afterwards.

Example request

curl -X POST https://app.smartcapitalcenter.com/api/v2/public/api-keys \
  -H "Authorization: Bearer $SCC_ACCESS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "Valuation integration", "description": "Used by our valuation workflow", "expiresInDays": 365}'

Response 200

API key created successfully.

Standard envelope with data containing:

Field Type Description
id integer Unique identifier of the API key.
keyValue string The API key to send in the X-API-KEY header. Shown only in this response. Example: sq_1a2b3c4d5e6f7g8h9i0j.
name string Name of the API key.
description string Description of the API key's purpose.
createdAt string When the API key was created.
expiresAt string When the API key expires (null if no expiration).
isActive boolean Whether the API key is active.

Errors

Code Meaning
400 Invalid request
401 Missing or invalid credentials

Next: Use X-API-KEY: <key> on all /api/v2/public/* calls.

# createApiKey `POST /api/v2/public/api-keys` Creates a named API key for the signed-in user. The key goes in the `X-API-KEY` header on every other call. **Auth:** `Authorization: Bearer <access_token>` (or `X-API-KEY`) **Use when:** Right after `register` or `login`, or when the user wants a separate key for a new integration. **Don't use when:** A working key already exists for this integration. Check with `getUserApiKeys` first. ## Request body Content type: `application/json` | Field | Type | Required | Description | |---|---|---|---| | `name` | string | yes | Name of the API key. Max 100 chars. Example: `My Application API Key`. | | `description` | string | no | Description of the API key's purpose. Max 500 chars. Example: `Used by the valuation integration`. | | `expiresInDays` | integer | no | Number of days until the API key expires (null for no expiration). Example: `365`. | ## Notes for agents - Send the bearer token from `register` or `login` in the `Authorization` header. - Omit `expiresInDays` for a key that never expires. Prefer an expiry when the user hasn't said otherwise, and tell them what you chose. - `data.keyValue` is returned only once. Show it to the user once, then mask it (`sq_****`) in anything you write afterwards. ## Example request ```bash curl -X POST https://app.smartcapitalcenter.com/api/v2/public/api-keys \ -H "Authorization: Bearer $SCC_ACCESS_TOKEN" \ -H "Content-Type: application/json" \ -d '{"name": "Valuation integration", "description": "Used by our valuation workflow", "expiresInDays": 365}' ``` ## Response `200` API key created successfully. Standard envelope with `data` containing: | Field | Type | Description | |---|---|---| | `id` | integer | Unique identifier of the API key. | | `keyValue` | string | The API key to send in the `X-API-KEY` header. Shown only in this response. Example: `sq_1a2b3c4d5e6f7g8h9i0j`. | | `name` | string | Name of the API key. | | `description` | string | Description of the API key's purpose. | | `createdAt` | string | When the API key was created. | | `expiresAt` | string | When the API key expires (null if no expiration). | | `isActive` | boolean | Whether the API key is active. | ## Errors | Code | Meaning | |---|---| | 400 | Invalid request | | 401 | Missing or invalid credentials | **Next:** Use `X-API-KEY: <key>` on all `/api/v2/public/*` calls.