Mint an additional API key

​

Creates another API key for the authenticated account, useful for rotating keys or giving separate agents their own credential. The secret is shown only in this response. Optionally name the key, restrict it to a set of scopes (with form:<id> constraints to pin it to specific forms), and set a ttlSeconds lifetime so it expires automatically. Omitting scopes mints a full-access key.

Body·
application/json

Optional key metadata, scopes, and lifetime.

  • name
    Type: string
    max length:  
    100

    Optional human-readable label for the key.

  • scopes
    Type: array string[] 1…

    Capabilities to grant this key. Action scopes are forms:read, forms:write, submissions:read, submissions:write, keys:manage; add form:<id> tokens to pin the key to specific forms. Omit for a full-access key (only a full-access key may do this). An empty array is rejected.

  • ttlSeconds
    Type: integer
    greater than:  
    0
    max:  
    31536000

    Seconds until the key expires and stops authenticating. Omit for a key that never expires. Max one year.

Responses
  • application/json
  • application/problem+json
  • application/problem+json
  • application/problem+json
Request Example for post/v1/keys
ffforms account create-api-key
{
  "id": "key_8Fh2Lm4Qp9",
  "name": "default",
  "keyPrefix": "fff_live_8Fh2",
  "scopes": [
    "submissions:read",
    "form:frm_3Qk9v2Xb7Lm"
  ],
  "expiresAt": null,
  "parentKeyId": null,
  "actor": null,
  "createdAt": "2026-07-28T10:15:30.000Z",
  "lastUsedAt": "2026-07-28T13:00:00.000Z",
  "revokedAt": null,
  "secret": "fff_live_8Fh2Lm4Qp9xYz0AbCdEf"
}