Creates a named API key for the signed-in user. The key goes in the X-API-KEY header on every other call.
Auth: Authorization: Bearer <access_token> (or X-API-KEY)
Use when: Right after register or login, or when the user wants a separate key for a new integration.
Don't use when: A working key already exists for this integration. Check with getUserApiKeys first.
Content type: application/json
| Field | Type | Required | Description |
|---|---|---|---|
name |
string | yes | Name of the API key. Max 100 chars. Example: My Application API Key. |
description |
string | no | Description of the API key's purpose. Max 500 chars. Example: Used by the valuation integration. |
expiresInDays |
integer | no | Number of days until the API key expires (null for no expiration). Example: 365. |
register or login in the Authorization header.expiresInDays for a key that never expires. Prefer an expiry when the user hasn't said otherwise, and tell them what you chose.data.keyValue is returned only once. Show it to the user once, then mask it (sq_****) in anything you write afterwards.curl -X POST https://app.smartcapitalcenter.com/api/v2/public/api-keys \
-H "Authorization: Bearer $SCC_ACCESS_TOKEN" \
-H "Content-Type: application/json" \
-d '{"name": "Valuation integration", "description": "Used by our valuation workflow", "expiresInDays": 365}'
200API key created successfully.
Standard envelope with data containing:
| Field | Type | Description |
|---|---|---|
id |
integer | Unique identifier of the API key. |
keyValue |
string | The API key to send in the X-API-KEY header. Shown only in this response. Example: sq_1a2b3c4d5e6f7g8h9i0j. |
name |
string | Name of the API key. |
description |
string | Description of the API key's purpose. |
createdAt |
string | When the API key was created. |
expiresAt |
string | When the API key expires (null if no expiration). |
isActive |
boolean | Whether the API key is active. |
| Code | Meaning |
|---|---|
| 400 | Invalid request |
| 401 | Missing or invalid credentials |
Next: Use X-API-KEY: <key> on all /api/v2/public/* calls.