TokenLab

Management

Create API Key

Create an API key for the current Workspace.

POSThttps://api.tokenlab.sh/v1/management/api-keys

Overview

Create an API key in the Workspace associated with the management token. The full secret appears once, in this response.

Request Body

FieldTypeDefault / LimitsNotes
namestringoptional, default Default Key, length 1-50Display name, trimmed server-side
limitAmountnumber | string | null0–100000 USDnull means unlimited; 0 prevents spend. Decimal strings support up to 6 decimal places. Omitting this field when creating a key means unlimited.
limitCurrencyenumdefault USDUSD only. Sending CNY returns 400 currency_retired.
modelsstring[]default []Optional model allowlist
deliveryPolicystring | nullauto, verified, official, nullnull inherits the Workspace delivery policy.
expiresAtstring | nullRFC3339 datetimenull means no expiry

Notes

  • Monetary fields are USD-only. CNY inputs are retired and return 400 currency_retired.

  • models: [] adds no key-level model restriction.

  • limitAmount: 0 creates a key that is valid but cannot spend quota until updated.

Example

Request

cURL
curl -X POST "https://api.tokenlab.sh/v1/management/api-keys" \
  -H "Authorization: Bearer mt-your-management-token" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Backend Worker",
    "limitAmount": 500,
    "models": ["veo3.1", "kling-3.0-video"],
    "expiresAt": "2026-12-31T23:59:59Z"
  }'

Request / Response

This page provides the OpenAPI schema and copyable request examples. Send management requests from your terminal or client with a Management Token; direct sending is not available on this page.

Response example

Response

201 Created
{
  "id": "key_abc123def456",
  "name": "Backend Worker",
  "key": "sk-live-redacted",
  "key_prefix": "sk-live...",
  "status": "active",
  "limit_amount": 500,
  "limit_amount_decimal": "500",
  "used_amount": 0,
  "used_amount_decimal": "0",
  "models": [
    "veo3.1",
    "kling-3.0-video"
  ],
  "expires_at": "2026-12-31T23:59:59.000Z",
  "last_used_at": null,
  "created_at": "2026-07-08T03:00:00.000Z",
  "delivery_policy": null
}

Important fields

keystring
Full secret API key value. It is returned only once on creation.
idstring
API key identifier used in follow-up Management API calls.
namestring
Display name for the API key.
key_prefixstring
Non-secret key prefix for display and support.
statusstring
One of active, inactive, suspended, or revoked.
limit_amountnumber | null
Spending cap in USD as a JSON number for display. null means unlimited.
limit_amount_decimalstring | null
Exact spending cap in USD as a decimal string. null means unlimited.
used_amountnumber
Accumulated usage in USD as a JSON number for display.
used_amount_decimalstring
Exact accumulated usage in USD as a decimal string.
modelsstring[]
Per-key model allowlist. Empty array means no additional key-level model restriction.
delivery_policystring | null
auto, verified, official, null. null inherits the Workspace delivery policy.
expires_atstring | null
ISO timestamp when the key expires, or null for no expiry.
last_used_atstring | null
ISO timestamp for the most recent use, or null when unused.
created_atstring
ISO creation timestamp.

Authorization

ManagementTokenAuth
AuthorizationBearer <token>

Management token authentication. Create or manage Management Tokens in Dashboard > API > Management Tokens.

In: header

Request Body

application/json

Response

application/json

application/json

application/json

application/json