Browse Documentation

Reference / browser control plane / generated

POST/v1/projects/{projectId}/api-keys

Create a project API key.

Creates a project-scoped API key and returns its plaintext exactly once. Only its prefix and SHA-256 digest are persisted.

Operation IDcreateProjectApiKey
Success201
AuthenticationBrowser session
CSRF headerX-Wildflower-Csrf

Request contract

  • projectId is a required path parameter.

The JSON request body uses the CreateProjectApiKeyInput model.

Same-origin request example

This operator-oriented example makes the cookie and CSRF boundaries explicit. Use an isolated browser test session, keep both values out of shell history, and replace generated path variables before execution.

terminal
curl --request POST \  --cookie "wildflower_session=${WILDFLOWER_SESSION}" \  --header "X-Wildflower-Csrf: ${WILDFLOWER_CSRF_TOKEN}" \  --header "Content-Type: application/json" \  --data @request.json \  "https://wildflower.computer/v1/projects/${WILDFLOWER_PROJECT_ID}/api-keys"

SDK boundary

This operation powers the account console and is not emitted in the TypeScript, Python, Rust, Go, or Zig project-key SDKs. Use the generated public API reference for sandbox automation.