Revoke a workspace API key
Full sessions only; org.settings.manage.
View as MarkdownAuthorization
bearer In: header
Path Parameters
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X DELETE "https://example.com/v1/workspaces/string/api-keys/string"{ "message": "string"}Create a workspace API key
Full sessions only; team workspaces only; org.settings.manage. role honored (member or admin, never owner). 200 with show-once secret. `billing` is refused with `code: billing_key_unusable`. A key exists to call APIs and there is no API a billing principal can call: every product gates on the tool check, which refuses a role holding no product seat, and org.billing.manage is carried by the matrix but used by no route. The key would authenticate and 403 on everything else, so it is refused at creation rather than discovered in production.
Audit log
org.settings.manage. Reads platform.audit_log, so entries span every Easerix tool, not just identity. Latest 100 by default, no pagination. meta is a JSON-encoded string; actor_id must be resolved by the client, and may name a user who no longer exists.