Create an API key
const url = 'https://api.connect.ms/v2/api-keys';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"name":"example","limits":{"dailyParts":1,"monthlyParts":1},"strictMode":true,"apiVersion":"example","signing":{"algorithm":"hmac_sha256","publicKey":"example"}}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.connect.ms/v2/api-keys \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "name": "example", "limits": { "dailyParts": 1, "monthlyParts": 1 }, "strictMode": true, "apiVersion": "example", "signing": { "algorithm": "hmac_sha256", "publicKey": "example" } }'Issues a new API key for the workspace. The full key, and the signing secret for hmac_sha256, are returned once in this response; the secret is shown again only when the key is rotated.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Header Parameters
Section titled “Header Parameters”The API version to use, for example 2026-10-01. Defaults to the version set on your API key.
A unique value of up to 255 characters, so a retried request is not acted on twice. Required for keys in Strict API Mode.
Request Bodyrequired
Section titled “Request Bodyrequired”The API key to create.
The API key to create.
object
A display name for the key, up to 64 characters.
SMS send limits for the key. Null or 0 removes a limit.
object
The most SMS parts the key may send per UTC day, up to 100000000. Null or 0 for no limit.
The most SMS parts the key may send per UTC calendar month, up to 100000000. Null or 0 for no limit.
Require every v2 request with this key to be signed, and every POST or PATCH to carry an Idempotency-Key. Needs signing to be set; defaults to false.
The Connect-Version to pin the key to. Defaults to the current version.
How requests with the key should be signed.
object
The algorithm requests are signed with: hmac_sha256 (a shared secret issued by Connect) or ecdsa_p256_sha256 (your own P-256 key pair; you supply the public key).
Your P-256 public key in SubjectPublicKeyInfo PEM format. Required for ecdsa_p256_sha256 and must be omitted for hmac_sha256.
Responses
Section titled “Responses”The key was created. The Location header holds its URL.
An API key of the workspace.
object
The unique id of the key.
The display name of the key, or null.
The first six characters of the key, for telling keys apart.
The last four characters of the key.
The key’s SMS send limits and how much of them has been used.
object
The most SMS parts the key may send per UTC day. Null means unlimited.
The most SMS parts the key may send per UTC calendar month. Null means unlimited.
SMS parts counted against the key so far today (UTC), including parts reserved for sends being processed.
SMS parts counted against the key so far this calendar month (UTC), including parts reserved for sends being processed.
True when every v2 request with this key must be signed and every POST or PATCH must carry an Idempotency-Key.
How requests with the key are signed.
object
The algorithm requests are signed with: hmac_sha256 (a shared secret issued by Connect) or ecdsa_p256_sha256 (your own P-256 key pair; you supply the public key).
The P-256 public key in SubjectPublicKeyInfo PEM format. Null for hmac_sha256.
The Connect-Version the key is pinned to. Null means it follows the current version.
When (UTC) the key was created.
When (UTC) the key becomes usable.
When (UTC) the key stops working, or null when it does not expire. Set on a key that has been rotated.
When (UTC) the key was last used. Not yet tracked, so always null.
The full key. Only returned by the response that issued it (create and rotate); null everywhere else.
The hmac_sha256 signing secret. Only returned by create, rotate (which carries the existing secret over), rotate-signing-secret, or an update that switched the key to hmac_sha256; null everywhere else.
Example
{ "signing": { "algorithm": "hmac_sha256" }}The request is not valid. The detail field says why, and errors lists any problems by field name.
Why a request failed, in the RFC 9457 problem details format.
object
A URI identifying the kind of problem, ending in a code such as validation_failed, not_found, sending_blocked or rate_limited.
A short, fixed summary of the kind of problem.
The HTTP status code of the response.
What went wrong with this particular request, when there is more to say than the title.
For validation failures, the problems found, keyed by field name (nested fields as template.name, list items as messages[3]).
object
The id recorded for this error, matching the Request-Id header when one is sent. Quote it when contacting support.
Example generated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "errors": { "additionalProperty": [ "example" ] }, "requestId": "example"}The API key or bearer token is missing or not valid, or the request signature could not be verified.
Why a request failed, in the RFC 9457 problem details format.
object
A URI identifying the kind of problem, ending in a code such as validation_failed, not_found, sending_blocked or rate_limited.
A short, fixed summary of the kind of problem.
The HTTP status code of the response.
What went wrong with this particular request, when there is more to say than the title.
For validation failures, the problems found, keyed by field name (nested fields as template.name, list items as messages[3]).
object
The id recorded for this error, matching the Request-Id header when one is sent. Quote it when contacting support.
Example generated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "errors": { "additionalProperty": [ "example" ] }, "requestId": "example"}The caller is not allowed to do this, or the workspace is not enabled for v2 API keys, or key creation is blocked for the workspace.
Why a request failed, in the RFC 9457 problem details format.
object
A URI identifying the kind of problem, ending in a code such as validation_failed, not_found, sending_blocked or rate_limited.
A short, fixed summary of the kind of problem.
The HTTP status code of the response.
What went wrong with this particular request, when there is more to say than the title.
For validation failures, the problems found, keyed by field name (nested fields as template.name, list items as messages[3]).
object
The id recorded for this error, matching the Request-Id header when one is sent. Quote it when contacting support.
Example generated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "errors": { "additionalProperty": [ "example" ] }, "requestId": "example"}A request with this Idempotency-Key is still being processed. Retry after the Retry-After header.
Why a request failed, in the RFC 9457 problem details format.
object
A URI identifying the kind of problem, ending in a code such as validation_failed, not_found, sending_blocked or rate_limited.
A short, fixed summary of the kind of problem.
The HTTP status code of the response.
What went wrong with this particular request, when there is more to say than the title.
For validation failures, the problems found, keyed by field name (nested fields as template.name, list items as messages[3]).
object
The id recorded for this error, matching the Request-Id header when one is sent. Quote it when contacting support.
Example generated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "errors": { "additionalProperty": [ "example" ] }, "requestId": "example"}This Idempotency-Key was already used for a different request. Use a new key.
Why a request failed, in the RFC 9457 problem details format.
object
A URI identifying the kind of problem, ending in a code such as validation_failed, not_found, sending_blocked or rate_limited.
A short, fixed summary of the kind of problem.
The HTTP status code of the response.
What went wrong with this particular request, when there is more to say than the title.
For validation failures, the problems found, keyed by field name (nested fields as template.name, list items as messages[3]).
object
The id recorded for this error, matching the Request-Id header when one is sent. Quote it when contacting support.
Example generated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "errors": { "additionalProperty": [ "example" ] }, "requestId": "example"}This API key requires an Idempotency-Key header on every POST and PATCH.
Why a request failed, in the RFC 9457 problem details format.
object
A URI identifying the kind of problem, ending in a code such as validation_failed, not_found, sending_blocked or rate_limited.
A short, fixed summary of the kind of problem.
The HTTP status code of the response.
What went wrong with this particular request, when there is more to say than the title.
For validation failures, the problems found, keyed by field name (nested fields as template.name, list items as messages[3]).
object
The id recorded for this error, matching the Request-Id header when one is sent. Quote it when contacting support.
Example generated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "errors": { "additionalProperty": [ "example" ] }, "requestId": "example"}The service is temporarily unavailable. Retry after the Retry-After header.
Why a request failed, in the RFC 9457 problem details format.
object
A URI identifying the kind of problem, ending in a code such as validation_failed, not_found, sending_blocked or rate_limited.
A short, fixed summary of the kind of problem.
The HTTP status code of the response.
What went wrong with this particular request, when there is more to say than the title.
For validation failures, the problems found, keyed by field name (nested fields as template.name, list items as messages[3]).
object
The id recorded for this error, matching the Request-Id header when one is sent. Quote it when contacting support.
Example generated
{ "type": "example", "title": "example", "status": 1, "detail": "example", "errors": { "additionalProperty": [ "example" ] }, "requestId": "example"}