> ## Documentation Index
> Fetch the complete documentation index at: https://docs.roark.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a personal credential

> Mints a credential that acts as you, for a CLI or an automation. The key value is returned exactly once, in the `key` field: capture it now, it is unreadable afterwards. Requires a personal credential (a project API key is refused) and admin on the project the credential defaults to. The new credential can never exceed the one that created it: not in scope, not in permissions, and not in lifetime. Omit a field to copy it from the calling credential.



## OpenAPI

````yaml /api-reference/openapi.documented.json post /v1/me/api-keys
openapi: 3.1.0
info:
  title: Roark Analytics API
  description: >-
    The Roark Analytics API gives you access to the same API that powers the
    award winning Roark Analytics platform.
  version: 1.0.0
servers:
  - description: Production
    url: https://api.roark.ai
security:
  - Bearer: []
tags:
  - name: Agent
  - name: Agent Endpoint
  - name: Call
  - name: Chat
  - name: Metric
  - name: Metric Policy
  - name: Metric Collection Job
  - name: Customer Flow
  - name: Customer Flow Edge Case
  - name: Simulation
  - name: Simulation Persona
  - name: Simulation Environment
  - name: Simulation Scenario
  - name: Simulation Run Plan
  - name: Simulation Template
  - name: Simulation Run Plan Job
  - name: Simulation Job
  - name: HTTP Request Definition
  - name: Webhook
  - name: Issue
  - name: Autoimprove
  - name: Agent Config
  - name: Knowledge Base
  - name: Config
  - name: Organization Project
  - name: Organization Project Member
  - name: Organization Project API Key
  - name: Organization Config
  - name: CLI Auth
  - name: Me
  - name: Project
  - name: Usage
  - name: Benchmark
  - name: Health
  - name: Prospect Simulation
paths:
  /v1/me/api-keys:
    post:
      tags:
        - Me
      summary: Create a personal credential
      description: >-
        Mints a credential that acts as you, for a CLI or an automation. The key
        value is returned exactly once, in the `key` field: capture it now, it
        is unreadable afterwards. Requires a personal credential (a project API
        key is refused) and admin on the project the credential defaults to. The
        new credential can never exceed the one that created it: not in scope,
        not in permissions, and not in lifetime. Omit a field to copy it from
        the calling credential.
      operationId: postV1MeApi-keys
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateMyApiKeyInput'
      responses:
        '200':
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/CreateMyApiKeyResponse'
                required:
                  - data
          description: The created credential, with its key value (returned only here)
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                description: Validation error
              example:
                type: validation
                code: invalid_parameter
                message: The request was invalid
                param: email
          description: Bad Request
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                description: Authentication error
              example:
                type: authentication
                code: unauthorized
                message: Authentication required
          description: Unauthorized
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                description: Permission error
              example:
                type: forbidden
                code: permission_denied
                message: You do not have permission to access this resource
          description: Forbidden
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                description: Not found error
              example:
                type: not_found
                code: resource_not_found
                message: The requested resource could not be found
          description: Not Found
        '429':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                description: Rate limit error
              example:
                type: rate_limit
                code: too_many_requests
                message: Rate limit exceeded
          description: Too Many Requests
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
                description: Server error
              example:
                type: internal
                code: internal_error
                message: Internal server error
          description: Internal Server Error
      x-codeSamples:
        - lang: JavaScript
          source: >-
            import Roark from '@roarkanalytics/sdk';


            const client = new Roark({
              bearerToken: process.env['ROARK_API_BEARER_TOKEN'], // This is the default and can be omitted
            });


            const response = await client.me.createAPIKey({ name: 'CI deploy
            gate' });


            console.log(response.data);
        - lang: Python
          source: |-
            import os
            from roark_analytics import Roark

            client = Roark(
                bearer_token=os.environ.get("ROARK_API_BEARER_TOKEN"),  # This is the default and can be omitted
            )
            response = client.me.create_api_key(
                name="CI deploy gate",
            )
            print(response.data)
components:
  schemas:
    CreateMyApiKeyInput:
      type: object
      properties:
        name:
          type: string
          minLength: 1
          maxLength: 255
          description: >-
            A label you will recognise later. It is the only thing that tells
            two credentials apart in the list you revoke from.
          example: CI deploy gate
        projectId:
          type: string
          description: >-
            Project the credential assumes when a request sends no
            X-Roark-Project-Id header. Defaults to the calling credential's own
            default project. You must be an admin of whichever project is used.
        scopes:
          type: array
          items:
            type: string
            enum:
              - READ
              - WRITE
          minItems: 1
          description: >-
            Coarse tier. Defaults to the calling credential's own tier, and can
            never exceed it: a READ credential cannot mint a WRITE one.
          example:
            - READ
        permissions:
          type: array
          items:
            type: string
          description: >-
            Granular 'resource:action' permissions. Defaults to the calling
            credential's own set, and can never exceed it. A ceiling, not an
            entitlement: the holder still only reaches what their project
            membership allows.
          example:
            - call:read
            - metric:read
        expiresAt:
          type: string
          format: date-time
          description: >-
            ISO 8601 expiry. Defaults to the calling credential's own expiry (no
            expiry, for a `roark auth login` credential) and may not outlive it,
            so a short-lived connector credential cannot mint a permanent one.
          example: '2026-12-31T23:59:59.000Z'
      required:
        - name
      description: A personal credential to mint for the caller
    CreateMyApiKeyResponse:
      allOf:
        - $ref: '#/components/schemas/MeApiKey'
      properties:
        key:
          type: string
          description: The credential value. Returned only here, only once.
      required:
        - key
      description: The created credential, with its key
      example:
        id: 7c6d5e4f-3a2b-4109-8765-4f3e2d1c0b9a
        name: CI deploy gate
        createdAt: '2026-10-05T09:30:00.000Z'
        lastUsedAt: null
        expiresAt: null
        status: ACTIVE
        organizationId: 9f8e7d6c-5b4a-4312-9081-7f6e5d4c3b2a
        defaultProjectId: 1a2b3c4d-5e6f-4701-8293-a4b5c6d7e8f9
        scopes:
          - READ
        permissions:
          - call:read
          - metric:read
        key: roark0f1e2d3c4b5a69788796a5b4c3d2e1f09182
    ErrorResponse:
      type: object
      properties:
        type:
          type: string
          enum:
            - validation
            - authentication
            - forbidden
            - not_found
            - conflict
            - payment_required
            - rate_limit
            - internal
          description: The error type category
          examples:
            - validation
            - authentication
        code:
          type: string
          description: Machine-readable error code identifier
          examples:
            - invalid_parameter
            - missing_required_field
            - unauthorized
        message:
          type: string
          description: Human-readable error message
          examples:
            - The request was invalid
            - Authentication required
        param:
          type: string
          description: The parameter that caused the error (if applicable)
          examples:
            - email
            - user_id
        details:
          description: Additional error context information
      required:
        - type
        - code
        - message
    MeApiKey:
      type: object
      properties:
        id:
          type: string
          description: Roark ID of the credential. Pass it to DELETE to revoke.
        name:
          type: string
          description: The label chosen when it was created
        createdAt:
          type: string
          description: ISO 8601 timestamp
        lastUsedAt:
          type:
            - string
            - 'null'
          description: ISO 8601 timestamp, null if never used
        expiresAt:
          type:
            - string
            - 'null'
          description: ISO 8601 timestamp, null if it never expires
        status:
          type:
            - string
            - 'null'
          enum:
            - ACTIVE
            - REVOKED
        organizationId:
          type:
            - string
            - 'null'
          description: The organization this credential is pinned to
        defaultProjectId:
          type:
            - string
            - 'null'
          description: >-
            The project a request acts on when it sends no X-Roark-Project-Id
            header. Null once that project is deleted.
        scopes:
          type: array
          items:
            type: string
          description: 'Coarse tier: READ, or WRITE for read and write'
        permissions:
          type: array
          items:
            type: string
          description: Granted 'resource:action' permissions
      required:
        - id
        - name
        - createdAt
        - lastUsedAt
        - expiresAt
        - status
        - organizationId
        - defaultProjectId
        - scopes
        - permissions
      description: A credential that acts as the caller
      example:
        id: 7c6d5e4f-3a2b-4109-8765-4f3e2d1c0b9a
        name: CLI on laptop
        createdAt: '2026-09-28T11:04:00.000Z'
        lastUsedAt: '2026-10-02T08:12:31.000Z'
        expiresAt: null
        status: ACTIVE
        organizationId: 9f8e7d6c-5b4a-4312-9081-7f6e5d4c3b2a
        defaultProjectId: 1a2b3c4d-5e6f-4701-8293-a4b5c6d7e8f9
        scopes:
          - READ
        permissions:
          - call:read
          - metric:read
  securitySchemes:
    Bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.