Skip to main content
POST
Mint a long-lived API key

Authorizations

Authorization
string
header
required

Either a Supabase user access token (from a password login, or the passwordless magic-link flow) or a long-lived forge_sk_… API key. Both are sent as Authorization: Bearer <value> and resolve to the same owner, so every endpoint accepts either. Session tokens expire in ~1h; API keys do not expire and are the credential for MCP clients, CI, and partner integrations.

Body

application/json
label
string

Human label so the key is identifiable later, e.g. "ci-pipeline". Max 80 chars.

Response

Minted. key is the ONLY copy.

id
string
label
string
masked
string

e.g. forge_sk_…a1b2

created_at
string
key
string

The raw key. Shown once, never recoverable.

warning
string