Skip to main content
POST
Error
This endpoint is available in Bifrost Enterprise only.
Required Permissions How permissions work

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a Required Permissions table (Resource:Operation, for example Dashboard:View) above its Authorizations section, and the caller's RBAC role or management API key scopes must include what it lists, otherwise the request is rejected with 403 Forbidden.

A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint. See Required permissions for how permissions are derived and which endpoints are exempt.

Body

application/json

Create body for a management API key. The key value is generated by the server and can never be supplied here.

name
string
required

Unique name for the key.

description
string | null

Optional note about what the key is for.

scopes
integer<uint>[]

Permission ids to grant, from GET /api/governance/rbac/permissions. A key carries only the permissions listed here — the creator's own role is not inherited. You cannot grant a permission you do not hold yourself; doing so returns 403.

expires_at
string<date-time> | null

Expiry timestamp in RFC3339 format. Omit or send null for a key that never expires.

Response

Key created. The full key value is returned once.

Creation response. This is the only time the full key value is returned — store it immediately, as it cannot be retrieved again.

api_key
object

A management API key. The key value itself is never returned after creation — only the truncated key_prefix is, so keys can be told apart in a list.

key
string

The full key value, shown only once. Send it in the Authorization header as Bearer <key>.

Example:

"bfst-A1b2C3d4E5f6G7h8I9j0K1l2M3n4O5p6Q7r8S9t0U1v2"