> ## Documentation Index
> Fetch the complete documentation index at: https://docs.refmatter.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a scoped workspace API key



## OpenAPI

````yaml /api-reference/openapi.json post /v1/workspaces/{workspaceId}/api-keys
openapi: 3.1.0
info:
  title: Refmatter API
  version: 0.1.0
  description: >-
    Reference memory for AI creative agents. Every operation carries
    x-implementation-status; only implemented operations are availability
    claims.
servers:
  - url: https://api.refmatter.com
security:
  - bearerApiKey: []
  - sessionCookie: []
tags:
  - name: auth
  - name: workspaces
  - name: ingestions
  - name: references
  - name: media
  - name: sourceRoutes
paths:
  /v1/workspaces/{workspaceId}/api-keys:
    post:
      tags:
        - workspaces
      summary: Create a scoped workspace API key
      operationId: apiKeysCreate
      parameters:
        - name: workspaceId
          in: path
          required: true
          description: Opaque workspace identifier
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ApiKeyCreate'
      responses:
        '201':
          description: API key created with one-time secret
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiKeyCreated'
        '400':
          description: Invalid request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '403':
          description: Action not permitted
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '404':
          description: Resource not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '409':
          description: Revision or idempotency conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '422':
          description: Request cannot be fulfilled by the current source contract
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '429':
          description: Rate limited
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '500':
          description: Internal error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '503':
          description: Route or dependency unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
      security:
        - sessionCookie: []
components:
  schemas:
    ApiKeyCreate:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        name:
          type: string
          minLength: 1
          maxLength: 160
        scopes:
          minItems: 1
          maxItems: 5
          type: array
          items:
            type: string
            enum:
              - references:read
              - references:write
              - ingestions:read
              - ingestions:write
              - media:read
        expiresAt:
          anyOf:
            - type: string
              pattern: >-
                ^\d{4}-(0[1-9]|1[0-2])-([0-2]\d|3[01])T([01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,9})?(?:Z|[+-](?:[01]\d|2[0-3]):[0-5]\d)$
            - type: 'null'
      required:
        - name
        - scopes
      additionalProperties: false
    ApiKeyCreated:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        id:
          type: string
          pattern: >-
            ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
        name:
          type: string
          minLength: 1
          maxLength: 160
        prefix:
          type: string
          minLength: 6
          maxLength: 24
        scopes:
          minItems: 1
          maxItems: 5
          type: array
          items:
            type: string
            enum:
              - references:read
              - references:write
              - ingestions:read
              - ingestions:write
              - media:read
        createdAt:
          type: string
          pattern: >-
            ^\d{4}-(0[1-9]|1[0-2])-([0-2]\d|3[01])T([01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,9})?(?:Z|[+-](?:[01]\d|2[0-3]):[0-5]\d)$
        expiresAt:
          anyOf:
            - type: string
              pattern: >-
                ^\d{4}-(0[1-9]|1[0-2])-([0-2]\d|3[01])T([01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,9})?(?:Z|[+-](?:[01]\d|2[0-3]):[0-5]\d)$
            - type: 'null'
        revokedAt:
          anyOf:
            - type: string
              pattern: >-
                ^\d{4}-(0[1-9]|1[0-2])-([0-2]\d|3[01])T([01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,9})?(?:Z|[+-](?:[01]\d|2[0-3]):[0-5]\d)$
            - type: 'null'
        lastUsedAt:
          anyOf:
            - type: string
              pattern: >-
                ^\d{4}-(0[1-9]|1[0-2])-([0-2]\d|3[01])T([01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,9})?(?:Z|[+-](?:[01]\d|2[0-3]):[0-5]\d)$
            - type: 'null'
        secret:
          type: string
          minLength: 32
          maxLength: 256
      required:
        - id
        - name
        - prefix
        - scopes
        - createdAt
        - expiresAt
        - revokedAt
        - lastUsedAt
        - secret
      additionalProperties: false
    ErrorEnvelope:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - invalid_input
                - unauthenticated
                - invalid_credential
                - credential_conflict
                - forbidden
                - policy_blocked
                - route_disabled
                - route_degraded
                - not_found
                - bootstrap_conflict
                - last_owner_conflict
                - revision_conflict
                - idempotency_conflict
                - unavailable_private
                - unavailable_restricted
                - unavailable_removed
                - unsupported_object
                - unsupported_media
                - limit_exceeded
                - rate_limited
                - source_changed
                - network_timeout
                - network_transport
                - media_invalid
                - storage_unavailable
                - retry_exhausted
                - internal_error
            message:
              type: string
              minLength: 1
              maxLength: 240
            retryable:
              type: boolean
            requestId:
              type: string
              minLength: 8
              maxLength: 128
              pattern: ^[A-Za-z0-9][A-Za-z0-9._:-]*$
            details:
              type: object
              propertyNames:
                type: string
              additionalProperties:
                type:
                  - string
                  - number
                  - boolean
          required:
            - code
            - message
            - retryable
            - requestId
            - details
          additionalProperties: false
      required:
        - error
      additionalProperties: false
  securitySchemes:
    bearerApiKey:
      type: http
      scheme: bearer
    sessionCookie:
      type: apiKey
      in: cookie
      name: social_session

````