Authentication
POST
/api/v1/auth/generate-key

Issue a new API key bound to the caller's organization.

This used to be anonymous and created a fresh org on every call - a security hole in any multi-tenant deployment. It now requires the caller to already be authenticated (Bearer or an existing API key). The created key inherits principal.organization_id and principal.user_id.

Authorization

AuthorizationBearer <token>

JWT access token. Use: Authorization: Bearer .

In: header

Header Parameters

Authorization?string|null
X-API-Key?string|null
X-EFFICIENTAI-API-KEY?string|null
X-Workspace-Id?string

Optional workspace scope. When omitted, the backend uses the active/default workspace from your organization context.

Formatuuid

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

curl -X POST "https://example.com/api/v1/auth/generate-key" \  -H "Content-Type: application/json" \  -d '{}'
{  "id": "string",  "key": "string",  "name": "string",  "is_active": true,  "created_at": "string"}

Community & contact

  1. Found a bug or have a feature request? Open a GitHub issue.
  2. Join our Discord for faster replies!