curl --request POST \
--url https://api.bitgpt.xyz/developers/api_keys \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"label": "Production API Key",
"description": "Key for production environment",
"scopes": [
"api_keys.read",
"api_keys.create"
],
"ip_allow_list": [
"192.168.1.1",
"10.0.0.1"
],
"expires_at": "2025-12-31 23:59:59"
}
'import requests
url = "https://api.bitgpt.xyz/developers/api_keys"
payload = {
"label": "Production API Key",
"description": "Key for production environment",
"scopes": ["api_keys.read", "api_keys.create"],
"ip_allow_list": ["192.168.1.1", "10.0.0.1"],
"expires_at": "2025-12-31 23:59:59"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
label: 'Production API Key',
description: 'Key for production environment',
scopes: ['api_keys.read', 'api_keys.create'],
ip_allow_list: ['192.168.1.1', '10.0.0.1'],
expires_at: '2025-12-31 23:59:59'
})
};
fetch('https://api.bitgpt.xyz/developers/api_keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.bitgpt.xyz/developers/api_keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'label' => 'Production API Key',
'description' => 'Key for production environment',
'scopes' => [
'api_keys.read',
'api_keys.create'
],
'ip_allow_list' => [
'192.168.1.1',
'10.0.0.1'
],
'expires_at' => '2025-12-31 23:59:59'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.bitgpt.xyz/developers/api_keys"
payload := strings.NewReader("{\n \"label\": \"Production API Key\",\n \"description\": \"Key for production environment\",\n \"scopes\": [\n \"api_keys.read\",\n \"api_keys.create\"\n ],\n \"ip_allow_list\": [\n \"192.168.1.1\",\n \"10.0.0.1\"\n ],\n \"expires_at\": \"2025-12-31 23:59:59\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.bitgpt.xyz/developers/api_keys")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"label\": \"Production API Key\",\n \"description\": \"Key for production environment\",\n \"scopes\": [\n \"api_keys.read\",\n \"api_keys.create\"\n ],\n \"ip_allow_list\": [\n \"192.168.1.1\",\n \"10.0.0.1\"\n ],\n \"expires_at\": \"2025-12-31 23:59:59\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.bitgpt.xyz/developers/api_keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"label\": \"Production API Key\",\n \"description\": \"Key for production environment\",\n \"scopes\": [\n \"api_keys.read\",\n \"api_keys.create\"\n ],\n \"ip_allow_list\": [\n \"192.168.1.1\",\n \"10.0.0.1\"\n ],\n \"expires_at\": \"2025-12-31 23:59:59\"\n}"
response = http.request(request)
puts response.read_body{
"status": 200,
"data": {
"id": "api_key_0197c0ec-a197-719f-84a9-99270a79b42a",
"secret": "sk_live_MDE5N2MwZWMtYTE5Ny03NDVlLWE1YmMtYzQyNTQ4M2JiZjAxX2JpdGdwdA",
"scopes": [
"products.create"
],
"ip_allow_list": [
"127.0.0.1"
],
"expires_at": "2026-05-30 20:23:16",
"created_at": "2025-06-30 15:00:22",
"updated_at": null
},
"error": null,
"log": null,
"validator": null,
"support_id": null,
"message": "Resource created successfully",
"env": "development"
}{
"status": 400,
"error": "Invalid email address",
"message": null,
"env": "development",
"log": {
"request_id": "req_1234567890"
},
"validator": {
"email": "Invalid email address",
"password": "Password is required"
},
"support_id": "support_uuidv7-something-else",
"data": {}
}{
"status": 401,
"error": "Invalid email address",
"message": null,
"env": "development",
"log": {
"request_id": "req_1234567890"
},
"validator": {
"email": "Invalid email address",
"password": "Password is required"
},
"support_id": "support_uuidv7-something-else",
"data": {}
}{
"status": 403,
"error": "Invalid email address",
"message": null,
"env": "development",
"log": {
"request_id": "req_1234567890"
},
"validator": {
"email": "Invalid email address",
"password": "Password is required"
},
"support_id": "support_uuidv7-something-else",
"data": {}
}Create a new API key
Create a new API key for the organization
curl --request POST \
--url https://api.bitgpt.xyz/developers/api_keys \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"label": "Production API Key",
"description": "Key for production environment",
"scopes": [
"api_keys.read",
"api_keys.create"
],
"ip_allow_list": [
"192.168.1.1",
"10.0.0.1"
],
"expires_at": "2025-12-31 23:59:59"
}
'import requests
url = "https://api.bitgpt.xyz/developers/api_keys"
payload = {
"label": "Production API Key",
"description": "Key for production environment",
"scopes": ["api_keys.read", "api_keys.create"],
"ip_allow_list": ["192.168.1.1", "10.0.0.1"],
"expires_at": "2025-12-31 23:59:59"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
label: 'Production API Key',
description: 'Key for production environment',
scopes: ['api_keys.read', 'api_keys.create'],
ip_allow_list: ['192.168.1.1', '10.0.0.1'],
expires_at: '2025-12-31 23:59:59'
})
};
fetch('https://api.bitgpt.xyz/developers/api_keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.bitgpt.xyz/developers/api_keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'label' => 'Production API Key',
'description' => 'Key for production environment',
'scopes' => [
'api_keys.read',
'api_keys.create'
],
'ip_allow_list' => [
'192.168.1.1',
'10.0.0.1'
],
'expires_at' => '2025-12-31 23:59:59'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.bitgpt.xyz/developers/api_keys"
payload := strings.NewReader("{\n \"label\": \"Production API Key\",\n \"description\": \"Key for production environment\",\n \"scopes\": [\n \"api_keys.read\",\n \"api_keys.create\"\n ],\n \"ip_allow_list\": [\n \"192.168.1.1\",\n \"10.0.0.1\"\n ],\n \"expires_at\": \"2025-12-31 23:59:59\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.bitgpt.xyz/developers/api_keys")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"label\": \"Production API Key\",\n \"description\": \"Key for production environment\",\n \"scopes\": [\n \"api_keys.read\",\n \"api_keys.create\"\n ],\n \"ip_allow_list\": [\n \"192.168.1.1\",\n \"10.0.0.1\"\n ],\n \"expires_at\": \"2025-12-31 23:59:59\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.bitgpt.xyz/developers/api_keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"label\": \"Production API Key\",\n \"description\": \"Key for production environment\",\n \"scopes\": [\n \"api_keys.read\",\n \"api_keys.create\"\n ],\n \"ip_allow_list\": [\n \"192.168.1.1\",\n \"10.0.0.1\"\n ],\n \"expires_at\": \"2025-12-31 23:59:59\"\n}"
response = http.request(request)
puts response.read_body{
"status": 200,
"data": {
"id": "api_key_0197c0ec-a197-719f-84a9-99270a79b42a",
"secret": "sk_live_MDE5N2MwZWMtYTE5Ny03NDVlLWE1YmMtYzQyNTQ4M2JiZjAxX2JpdGdwdA",
"scopes": [
"products.create"
],
"ip_allow_list": [
"127.0.0.1"
],
"expires_at": "2026-05-30 20:23:16",
"created_at": "2025-06-30 15:00:22",
"updated_at": null
},
"error": null,
"log": null,
"validator": null,
"support_id": null,
"message": "Resource created successfully",
"env": "development"
}{
"status": 400,
"error": "Invalid email address",
"message": null,
"env": "development",
"log": {
"request_id": "req_1234567890"
},
"validator": {
"email": "Invalid email address",
"password": "Password is required"
},
"support_id": "support_uuidv7-something-else",
"data": {}
}{
"status": 401,
"error": "Invalid email address",
"message": null,
"env": "development",
"log": {
"request_id": "req_1234567890"
},
"validator": {
"email": "Invalid email address",
"password": "Password is required"
},
"support_id": "support_uuidv7-something-else",
"data": {}
}{
"status": 403,
"error": "Invalid email address",
"message": null,
"env": "development",
"log": {
"request_id": "req_1234567890"
},
"validator": {
"email": "Invalid email address",
"password": "Password is required"
},
"support_id": "support_uuidv7-something-else",
"data": {}
}Authorizations
Send your access token as header Authorization: Bearer {accessToken}
Body
Request body for creating a new API key
Human-readable label for the API key
255Human-readable description for the API key
List of scopes this API key has access to
invoices.create, invoices.update, invoices.read, payments.create, payments.update, payments.read, products.create, products.read, products.update, products.delete, api_keys.create, api_keys.update, api_keys.delete, api_keys.read, webhooks.create, webhooks.read, webhooks.update, webhooks.delete, webhooks_queue.read, webhooks_queue.update, notifications.read, notifications.update, notifications_settings.read, notifications_settings.update, organizations.create, organizations.read, organizations.update, organizations.deactivate, users.update, users.deactivate, users.sessions.read, users.sessions.deactivate List of IP addresses allowed to use this API key
Timestamp when the API key expires
"2025-06-29 16:03:44"
Response
Successful API key creation response
Status code of the response
200, 201, 202 Response data containing the requested object
Show child attributes
Show child attributes
{
"id": "api_key_0197c0f1-9589-7990-b421-4b806f637b0c",
"label": "My API Key",
"description": "Key for accessing product APIs",
"secret": "sk_live_MDE5N2MwZjEtOTU4OS03N2U0LWJiY2YtNGQ0OWQ4YTM5NzUzX2JpdGdwdA",
"scopes": ["products.create"],
"ip_allow_list": ["127.0.0.1"],
"expires_at": "2026-05-30 20:23:16",
"created_at": "2025-06-30 15:05:47",
"updated_at": null,
"metrics": {
"api_key_id": "api_key_0197c0f1-9589-7990-b421-4b806f637b0c",
"total_requests": 150,
"last_used_at": "2025-06-30 16:03:44"
}
}
Message of the response, human readable
"Resource created successfully"
API environment
development, production Error message of the response, human readable
"Invalid email address"
Useful informaiton, not always present, to debug the response
{ "request_id": "req_1234567890" }
"Some pertinent log message"
Validator response object, each key is the field name and value is the error message
{
"email": "Invalid email address",
"password": "Password is required"
}
Support ID linked to the response, used to identify it when talking with our team
"support_uuidv7-something-else"

