API ReferenceAPI Keys
Create an API key
POST /api/v1/user/api-keys — create a new key. Full value is returned ONCE.
POST /api/v1/user/api-keysCreate a new API key. The full key value (api_key field) is returned only in this response — store it immediately. After this, only key_prefix is ever visible.
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
name | string | ✓ | Display name (e.g., "Production server"). |
Response
{
"id": 7,
"name": "Production server",
"key_prefix": "zsk_a1b2",
"api_key": "zsk_a1b2c3d4e5f6g7h8i9j0...",
"created_at": "2026-06-16T10:30:00Z"
}Save the key now
This is the only time api_key is returned. If you lose it you must create a new key and revoke this one.
Examples
curl -X POST https://dashboard.zoxa.ai/api/v1/user/api-keys \
-H "X-API-Key: zsk_..." \
-H "Content-Type: application/json" \
-d '{ "name": "Production server" }'const { api_key } = await fetch(
"https://dashboard.zoxa.ai/api/v1/user/api-keys",
{
method: "POST",
headers: { "X-API-Key": "zsk_...", "Content-Type": "application/json" },
body: JSON.stringify({ name: "Production server" }),
},
).then((r) => r.json());
// store immediately
secretsManager.put("zoxa_api_key", api_key);import httpx
resp = httpx.post(
"https://dashboard.zoxa.ai/api/v1/user/api-keys",
headers={"X-API-Key": "zsk_..."},
json={"name": "Production server"},
).json()
print("SAVE THIS:", resp["api_key"])Errors
| Status | detail | When |
|---|---|---|
400 | "No organization selected" | Auth missing org. |