> ## Documentation Index
> Fetch the complete documentation index at: https://docs.protodesk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an API key

> Mints a new API key. The raw secret is returned once in the response and is never retrievable afterward. Requires the keys:manage scope.




## OpenAPI

````yaml POST /keys
openapi: 3.1.0
info:
  title: Protodesk API
  version: 0.1.0
  description: >
    The Protodesk Platform API: sync your customers in, attach your own business
    objects (orders, bookings, listings) to conversations, post and read
    messages across channels, and receive every workspace event via signed
    webhooks or a resumable SSE stream.


    Authenticate every request with a workspace-scoped API key: `Authorization:
    Bearer pk_live_...`. Create endpoints accept an `Idempotency-Key` header so
    retries are always safe. Lists use opaque cursor pagination (`data` /
    `hasMore` / `nextCursor`).


    Task-oriented guides: [docs.protodesk.io](https://docs.protodesk.io).
servers:
  - url: https://api.protodesk.io/v1
    description: Production
  - url: http://localhost:8080/v1
    description: Local development
security: []
tags:
  - name: Customers
    description: People or companies contacting a workspace across channels.
  - name: Conversations
    description: Customer conversations attached to channels and external business objects.
  - name: Messages
    description: Customer, agent, AI, system, and internal messages inside conversations.
  - name: Channel identities
    description: >-
      The same customer across WhatsApp, email, chat, and more — linked
      identities per channel.
  - name: Statuses & priorities
    description: The workspace's conversation statuses and priority levels.
  - name: Assignments
    description: >-
      Who a conversation has been assigned to, over time. Assign via POST
      /conversations/{conversationId}/assign.
  - name: Webhooks
    description: Webhook subscriptions for receiving workspace events.
  - name: Realtime
    description: Server-sent event stream of workspace events.
  - name: API Keys
    description: Create, list, and revoke workspace API keys.
  - name: Account
    description: The workspace and scopes behind your API key.
  - name: System
    description: Service metadata and health endpoints.
paths:
  /keys:
    post:
      tags:
        - API Keys
      summary: Create an API key
      description: >
        Mints a new API key. The raw secret is returned once in the response and
        is never retrievable afterward. Requires the keys:manage scope.
      operationId: createApiKey
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateApiKeyRequest'
      responses:
        '201':
          description: Created API key with its raw secret (shown once).
          headers:
            X-Request-Id:
              $ref: '#/components/headers/RequestId'
            Idempotency-Replayed:
              $ref: '#/components/headers/IdempotencyReplayed'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreatedApiKey'
        default:
          $ref: '#/components/responses/Error'
      security:
        - ApiKeyAuth: []
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: false
      description: >
        Optional retry key for safely replaying create requests. Reusing the
        same key with a different request body returns 409.
      schema:
        type: string
        minLength: 8
        maxLength: 255
        example: 8db8e596-7c1a-4fd5-a728-4d6c99f4e66b
  schemas:
    CreateApiKeyRequest:
      type: object
      required:
        - name
        - scopes
      properties:
        name:
          type: string
          description: Human-readable label for the key.
          example: CI deploy
        environment:
          type: string
          description: Defaults to the calling key's environment.
          enum:
            - live
            - test
        scopes:
          type: array
          minItems: 1
          items:
            $ref: '#/components/schemas/APIKeyScope'
    CreatedApiKey:
      type: object
      description: A newly created key. The secret is shown once and never again.
      required:
        - id
        - name
        - environment
        - scopes
        - display
        - secret
      properties:
        id:
          type: string
          example: key_o5mj4q7beg32vkjcd76a37t5zy
        name:
          type: string
        environment:
          type: string
          enum:
            - live
            - test
        scopes:
          type: array
          items:
            $ref: '#/components/schemas/APIKeyScope'
        display:
          type: string
          description: Masked key preview safe to display.
          example: pk_test_key...cret
        secret:
          type: string
          description: The raw API key. Store it now; it cannot be retrieved later.
          example: >-
            pk_test_key_o5mj4q7beg32vkjcd76a37t5zy_abcdefghijklmnopqrstuvwxyz234567
    APIKeyScope:
      type: string
      description: Workspace API key permission scope.
      enum:
        - customers:read
        - customers:write
        - conversations:read
        - conversations:write
        - messages:write
        - attachments:read
        - attachments:write
        - webhooks:manage
        - realtime:read
        - ai:use
        - keys:manage
        - help:read
        - help:drafts:write
    ErrorEnvelope:
      type: object
      required:
        - error
      properties:
        error:
          $ref: '#/components/schemas/Error'
    Error:
      type: object
      required:
        - code
        - message
        - requestId
      properties:
        code:
          type: string
          example: route.not_found
        message:
          type: string
          example: Not found
        requestId:
          type: string
          example: req_x6q5vl75f5d53m7oet2k4r5w6a
  headers:
    RequestId:
      description: Request id for tracing this request in logs and support.
      schema:
        type: string
        example: req_x6q5vl75f5d53m7oet2k4r5w6a
    IdempotencyReplayed:
      description: Present with true when a response was replayed from an idempotency key.
      schema:
        type: string
        enum:
          - 'true'
    RateLimitLimit:
      description: >-
        Request budget for the route class (read or write) applied to this
        request.
      schema:
        type: integer
        example: 40
    RateLimitRemaining:
      description: Requests remaining in the current budget after this request.
      schema:
        type: integer
        example: 39
    RateLimitReset:
      description: Seconds until the budget refills to its full limit.
      schema:
        type: integer
        example: 1
    RetryAfter:
      description: Seconds to wait before retrying, sent with 429 responses.
      schema:
        type: integer
        example: 1
  responses:
    Error:
      description: >-
        Error response. All /v1 responses carry RateLimit-Limit,
        RateLimit-Remaining, and RateLimit-Reset headers. A 429
        (rate_limit.exceeded) additionally carries Retry-After. Request bodies
        exceeding the route-class limit (1KB reads, 64KB writes) return 413
        (request.body_too_large).
      headers:
        X-Request-Id:
          $ref: '#/components/headers/RequestId'
        RateLimit-Limit:
          $ref: '#/components/headers/RateLimitLimit'
        RateLimit-Remaining:
          $ref: '#/components/headers/RateLimitRemaining'
        RateLimit-Reset:
          $ref: '#/components/headers/RateLimitReset'
        Retry-After:
          $ref: '#/components/headers/RetryAfter'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorEnvelope'
  securitySchemes:
    ApiKeyAuth:
      type: http
      scheme: bearer
      bearerFormat: Protodesk API key
      description: >
        Use a workspace API key in the Authorization header. Keys use
        pk_live_<key_id>_<secret> for production and pk_test_<key_id>_<secret>
        for test mode.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.