Skip to main content
POST
Create API key
The response shows the plaintext key once. It identifies your application and can Search public capabilities. To Act for a person, use their scoped OAuth grant. Existing user-bound keys remain valid until revoked.
Use Me → Developer to register an application and create its Search key without opening a settings modal. You can also register an application through the API with the same verified account session, then call this endpoint while that session is active.

Authorizations

__Secure-better-auth.session_token
string
cookie
required

The HTTP-only Darwin account session cookie set after sign-in. Local development uses better-auth.session_token without the __Secure- prefix.

Body

application/json
applicationId
string
required

An active application owned by the signed-in account.

Required string length: 1 - 200
name
string
required

A recognizable name for the environment or integration that will use this key.

Required string length: 1 - 120
Example:

"Production server"

scopes
enum<string>[]

Optional. New application keys are limited to directory:read; use OAuth for user-scoped Act.

Required array length: 1 element
Available options:
directory:read
Example:
expiresAt
string<date-time> | null

Optional future ISO 8601 expiration. Omit or set null for no scheduled expiration.

Example:

"2027-09-21T00:00:00.000Z"

Response

The API key was created. Store apiKey securely because Darwin will not return it again.

id
string
required

Stable non-secret identifier for the API key.

name
string
required

Human-readable key name supplied at creation.

prefix
string
required

Non-secret prefix you can use to identify the key in logs and settings.

scopes
string[]
required

Permissions granted to the key. Every API operation still enforces its required scope.

requestCount
integer
required

Lifetime number of requests authenticated with this key.

Required range: x >= 0
lastUsedAt
string<date-time> | null
required

When Darwin most recently authenticated a request with this key, or null if unused.

expiresAt
string<date-time> | null
required

When the key expires, or null when it has no scheduled expiration.

revokedAt
string<date-time> | null
required

When the key was revoked, or null while it has not been revoked.

createdAt
string<date-time>
required

When the key was created.

apiKey
string
required
read-only

Plaintext API key. Darwin returns this value only in the create response.

kind
enum<string>

New keys identify an application; legacy keys retain their previous user-bound behavior until revoked.

Available options:
application,
legacy_user
applicationId
string | null

The application identified by a new key, or null for a legacy user key.

Last modified on September 29, 2026