Skip to main content
POST
Create API Key (User)

Authorizations

Authorization
string
header
required

First-party access token for your own signed-in session, obtained from the /api/enterprise-auth/login endpoint. The REST API returns your own account data to you — it is a first-party consumer surface, not a third-party integration channel. Data from connected bank feeds (open-banking / CDR data) is your own data, returned only to you in your own authenticated session.

Body

application/json
name
string
required
Example:

"My MCP Integration"

scopes
enum<string>[]

Scopes for the API key. Defaults to mcp:full. Admin scope (*) is not allowed for user-created keys.

Available options:
mcp:read,
mcp:tools:list,
mcp:tools:call,
mcp:resources:read,
mcp:full
expiresInDays
integer
default:90
Required range: 1 <= x <= 365
Example:

90

Response

API key created

id
string
key
string

API key - only shown once! Save immediately.

name
string
scopes
string[]
expiresAt
string
createdAt
string
warning
string
Example:

"Save this key now - it will not be shown again!"