Creates an API key and returns the plaintext value once. Requires secret:write or secret.write. You can only assign API permissions you already hold. Expiry must be in the future if set.
Request
POST /secret
Headers
| Header | Value |
|---|---|
Authorization | Bearer <token> (or HMAC headers, see Authentication) |
Content-Type | application/json |
Request Body
| Field | Type | Required | Description |
|---|---|---|---|
title | string | Yes | Name. Cannot be empty. |
description | string | No | Description. |
expiry | string | No | Parseable datetime. Omit or null for no expiry. |
isActive | boolean | No | Default false. |
permissions | array | No | Colon-notation API permissions. |
preset | string | No | Preset name (Importer, Search, Shopify, or Makaira-Preset.…). Permissions are merged with permissions. Unknown preset returns HTTP 400. |
Example Request
{
"title": "Shop Connect",
"isActive": true,
"preset": "Importer"
}Response
Secret object including plainSecret (for example api_…). Copy it immediately.

