Create a personal credential
Mints a credential that acts as you, for a CLI or an automation. The key value is returned exactly once, in the key field: capture it now, it is unreadable afterwards. Requires a personal credential (a project API key is refused) and admin on the project the credential defaults to. The new credential can never exceed the one that created it: not in scope, not in permissions, and not in lifetime. Omit a field to copy it from the calling credential.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Body
A personal credential to mint for the caller
A label you will recognise later. It is the only thing that tells two credentials apart in the list you revoke from.
1 - 255"CI deploy gate"
Project the credential assumes when a request sends no X-Roark-Project-Id header. Defaults to the calling credential's own default project. You must be an admin of whichever project is used.
Coarse tier. Defaults to the calling credential's own tier, and can never exceed it: a READ credential cannot mint a WRITE one.
1READ, WRITE Granular 'resource:action' permissions. Defaults to the calling credential's own set, and can never exceed it. A ceiling, not an entitlement: the holder still only reaches what their project membership allows.
ISO 8601 expiry. Defaults to the calling credential's own expiry (no expiry, for a roark auth login credential) and may not outlive it, so a short-lived connector credential cannot mint a permanent one.
"2026-12-31T23:59:59.000Z"
Response
The created credential, with its key value (returned only here)
The created credential, with its key