API reference

API keys

Create an API key

Mints a key, optionally scoped to specific profiles. The secret is returned once and cannot be retrieved later.

Required permission: `connections:write`

POST/v1/api-keysconnections:write

Request

Authorization

Send your API key as a Bearer token in the Authorization header.

Headers

Idempotency-Keystringoptional

A unique key so a retried request is not applied twice. Stored for 24 hours.

Request body

namestringrequired

Label shown in the dashboard.

profileIdsstring[]optional

Restrict the key to these profiles. Omit for access to every profile in the account.

expiresInintegeroptional

Days until the key expires. Omit for no expiry.

allowedAccountIdsstring[]optional

Restrict the key to these connected accounts.

maxPostsPerDayintegeroptional

Cap usage per UTC day with this key.

Response

Returns 201.

ApiKeyrequired
secretstringrequired

The only time the full key is returned.

messagestringrequired

Errors

Failures use the standard error format.

StatusCodeWhen it happens
400invalid_requestThe request body or query string failed validation. The message names the offending field.
401invalid_api_keyThe key does not exist, was revoked, or is malformed. Keys start with cdyn_live_.
403insufficient_permissionThe key is missing the scope this endpoint needs, for example posts:write on a readonly key.
403profile_not_accessibleThe requested profile is outside this key’s scope, or belongs to another account.
429rate_limit_exceededToo many requests for this key. Honour the Retry-After header before retrying.
500internal_errorSomething failed on our side. Retry with the same Idempotency-Key; report the requestId if it persists.