POST /api-keys
Create an API key. The token is shown exactly once.
Parameters
Idempotency-Keyheader · string · optional — Makes this call safe to retry. Send the same key with the same body and the original response is replayed instead of the work happening twice. Keys are 1-256 characters and are remembered for 7 days. While the first attempt is still running, a second call with that key returns 409 idempotency_in_flight (Resend calls this concurrent_idempotent_requests); the same key with a different body returns 409 idempotency_payload_mismatch (Resend: invalid_idempotent_request).
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
| domain_scope | string | null | no | |
| name | string | yes | |
| permission | "full_access" | "sending_access" | yes | |
| scopes | array<"emails:send" | "emails:read" | "domains:read" | "domains:write" | "webhooks:read" | "webhooks:write" | …> | no |
Responses
201— Success400— Validation error401— Missing API key403— Forbidden404— Not found409— Conflict429— Rate limited500— Internal server error
Response headers
ratelimit-limit— Messages this API key may spend in one 60-second window.ratelimit-remaining— Messages left in the current window.ratelimit-reset— Seconds until the current window resets and the budget refills.
201 body
| Field | Type | Required | Notes |
|---|---|---|---|
| budget_per_period | integer | null | yes | |
| created_at | string | yes | |
| domain_scope | string | null | yes | |
| expires_at | string | null | yes | |
| id | string | yes | |
| last_used_at | string | null | yes | |
| name | string | yes | |
| period | "hourly" | "daily" | "monthly" | yes | |
| permission | "full_access" | "sending_access" | yes | |
| previous_key_expires_at | string | null | yes | |
| rate_ceiling_per_minute | integer | null | yes | |
| request_count_30d | integer | yes | |
| rotated_at | string | null | yes | |
| scopes | array<string> | yes | |
| system | boolean | yes | |
| token | string | yes | |
| token_prefix | string | yes |
Errors
Codes in the catalogue that answer with one of this operation’s error statuses. Every one of them carries a fix.
- validation_error 400
- invalid_idempotency_key 400
- invalid_cursor 400
- domain_already_exists 409
- domain_verified_elsewhere 409
- domain_not_verified 403
- account_suspended 403
- account_sandboxed 403
- trust_throttled 429
- missing_api_key 401
- session_required 401
- human_action_required 403
- csrf_origin_rejected 403
- mfa_required 401
- plan_not_purchasable 400
- trial_already_used 409
- plan_already_active 409
- term_not_on_sale 409
- subscription_active 409
- billing_customer_missing 404
- stripe_signature_invalid 400
- invalid_api_key 403
- restricted_api_key 403
- insufficient_role 403
- invite_email_mismatch 403
- already_in_account 409
- domain_scope_violation 403
- not_found 404
- session_expired 404
- idempotency_in_flight 409
- idempotency_payload_mismatch 409
- rate_ceiling_exceeded 429
- daily_quota_exceeded 429
- monthly_quota_exceeded 429
- rate_limit_exceeded 429
- approval_required 403
- trust_paused 403
- kill_switch_active 403
- internal_server_error 500
- support_ticket_not_found 404
- support_closed 409
- support_reopen_expired 409
- support_merge_conflict 409
- support_upload_rejected 400
- support_rate_limited 429