Skip to main content
POST
JavaScript

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json

A personal credential to mint for the caller

name
string
required

A label you will recognise later. It is the only thing that tells two credentials apart in the list you revoke from.

Required string length: 1 - 255
Example:

"CI deploy gate"

projectId
string

Project the credential assumes when a request sends no X-Roark-Project-Id header. Defaults to the calling credential's own default project. You must be an admin of whichever project is used.

scopes
enum<string>[]

Coarse tier. Defaults to the calling credential's own tier, and can never exceed it: a READ credential cannot mint a WRITE one.

Minimum array length: 1
Available options:
READ,
WRITE
Example:
permissions
string[]

Granular 'resource:action' permissions. Defaults to the calling credential's own set, and can never exceed it. A ceiling, not an entitlement: the holder still only reaches what their project membership allows.

Example:
expiresAt
string<date-time>

ISO 8601 expiry. Defaults to the calling credential's own expiry (no expiry, for a roark auth login credential) and may not outlive it, so a short-lived connector credential cannot mint a permanent one.

Example:

"2026-12-31T23:59:59.000Z"

Response

The created credential, with its key value (returned only here)

data
object
required

The created credential, with its key

Example: