POST
/v1/api-keysCreate an API key
Mints a key, optionally scoped to specific profiles. The secret is returned once and cannot be retrieved later.
Required permission: `connections:write`
- Base URL
- https://api.cutedyno.com
- Permission
connections:write- Idempotency
- Send an
Idempotency-Keyheader so a retry cannot apply twice. How it works
Request
curl -X POST "https://api.cutedyno.com/v1/api-keys" \
-H "Authorization: Bearer $CUTEDYNO_API_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{
"name": "Acme Corp",
"profileIds": [
"string"
],
"expiresIn": 0,
"allowedAccountIds": [
"string"
],
"maxPostsPerDay": 0,
"requireApproval": false
}'Headers
Idempotency-KeystringoptionalA unique key so a retried request is not applied twice. Stored for 24 hours.
Body
namestringrequiredLabel shown in the dashboard.
scopeobjectoptionalDefaults to full.
profileIdsstring[]optionalRestrict the key to these profiles. Omit for access to every profile in the account.
expiresInintegeroptionalDays until the key expires. Omit for no expiry.
allowedAccountIdsstring[]optionalRestrict the key to these connected accounts.
maxPostsPerDayintegeroptionalCap posts created per UTC day with this key.
requireApprovalbooleanoptionalForce posts from this key through approval.
Response
Returns 201 with the following body.
ApiKeyrequired
secretstringrequiredThe only time the full key is returned.
messagestringrequiredExample
{
"key": {
"id": "a1b2c3d4-0000-4000-8000-000000000000",
"name": "Acme Corp",
"keyPrefix": "string",
"scope": "full",
"profileIds": [
"string"
],
"expiresAt": "string",
"createdAt": "string"
},
"secret": "whsec_2f8a...",
"message": "Shipping today."
}Errors
Failures use the standard error envelope. Branch on code, never on the message.
| Status | Code | When it happens |
|---|---|---|
| 400 | invalid_request | The request body or query string failed validation. The message names the offending field. |
| 401 | invalid_api_key | The key does not exist, was revoked, or is malformed. Keys start with cdyn_live_. |
| 403 | insufficient_permission | The key is missing the scope this endpoint needs, for example posts:write on a readonly key. |
| 403 | profile_not_accessible | The requested profile is outside this key’s scope, or belongs to another account. |
| 429 | rate_limit_exceeded | Too many requests for this key. Honour the Retry-After header before retrying. |
| 500 | internal_error | Something failed on our side. Retry with the same Idempotency-Key; report the requestId if it persists. |