Mint an additional API key
Creates another API key for the authenticated account, useful for rotating keys or giving separate agents their own credential. The secret is shown only in this response. Optionally name the key, restrict it to a set of scopes (with form:<id> constraints to pin it to specific forms), and set a ttlSeconds lifetime so it expires automatically. Omitting scopes mints a full-access key.
Optional key metadata, scopes, and lifetime.
- Type: stringnamemax length:100
Optional human-readable label for the key.
- Type: array string[] 1…scopes
Capabilities to grant this key. Action scopes are
forms:read,forms:write,submissions:read,submissions:write,keys:manage; addform:<id>tokens to pin the key to specific forms. Omit for a full-access key (only a full-access key may do this). An empty array is rejected. - Type: integerttl
Seconds greater than:0max:31536000Seconds until the key expires and stops authenticating. Omit for a key that never expires. Max one year.
- application/json
- application/problem+json
- application/problem+json
- application/problem+json
ffforms account create-api-key
{
"id": "key_8Fh2Lm4Qp9",
"name": "default",
"keyPrefix": "fff_live_8Fh2",
"scopes": [
"submissions:read",
"form:frm_3Qk9v2Xb7Lm"
],
"expiresAt": null,
"parentKeyId": null,
"actor": null,
"createdAt": "2026-07-28T10:15:30.000Z",
"lastUsedAt": "2026-07-28T13:00:00.000Z",
"revokedAt": null,
"secret": "fff_live_8Fh2Lm4Qp9xYz0AbCdEf"
}