Create API key
API keys
Create API key
Session-only. Create a key. The response’s plaintext (the full
aro_sk_… secret) is shown exactly once; only its SHA-256 hash is
stored. Accounts can hold at most 10 active keys.
POST
Create API key
Authorizations
Browser session cookie minted by POST /auth/login (or passkey
login). httpOnly, SameSite=Lax, 24 h TTL. Endpoints marked
Session-only accept only this credential and return
403 session_required for API keys.
Body
application/json