> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developer.projectmanager.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developer.projectmanager.com/_mcp/server.

# Create Api Key

POST https://api.projectmanager.com/api/data/api-keys
Content-Type: application/json

Creates a new API key for the current user with the specified options.
            
An API key is a credential that you can use to make REST v4 API calls for ProjectManager.com.  When you create
a new API key, that API key is only visible in the response JSON for the `CreateApiKey` method.  If you do not
preserve this information, it cannot be recreated.
            
Some best practices for working with API keys:
* An API key is valid for a two year period after it is created.  We encourage you to rotate your API keys
regularly according to your company's security policies.
* You should create separate API keys for each system that works with your API.  If that API key is exposed
or if that program needs to be shut down, you can revoke that one key and reissue it.
* An API key is tied to the workspace that created it. A single API key can only interact with one workspace.

Reference: https://developer.projectmanager.com/api-reference/api-key/create-api-key

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Request

### Headers

- `x-integration-name` (string, optional) — The name of the calling system passed along as a header parameter

### Body (application/json)

This endpoint expects an ApiKeyCreateDto.

- `tokenName` (string, required) — Name of token

## Response

### 200

Success

- `error` (AstroError, optional, nullable) — If the API call failed, this will contain information about the error that occurred.
- `success` (boolean, optional) — True if the API call succeeded; false otherwise.
- `hasError` (boolean, optional) — True if the API call failed.
- `statusCode` (enum, optional) — The HTTP code of the response.
  - Allowed values: `Continue`, `SwitchingProtocols`, `Processing`, `EarlyHints`, `OK`, `Created`, `Accepted`, `NonAuthoritativeInformation`, `NoContent`, `ResetContent`, `PartialContent`, `MultiStatus`, `AlreadyReported`, `IMUsed`, `MultipleChoices`, `MovedPermanently`, `Found`, `SeeOther`, `NotModified`, `UseProxy`, `Unused`, `TemporaryRedirect`, `PermanentRedirect`, `BadRequest`, `Unauthorized`, `PaymentRequired`, `Forbidden`, `NotFound`, `MethodNotAllowed`, `NotAcceptable`, `ProxyAuthenticationRequired`, `RequestTimeout`, `Conflict`, `Gone`, `LengthRequired`, `PreconditionFailed`, `RequestEntityTooLarge`, `RequestUriTooLong`, `UnsupportedMediaType`, `RequestedRangeNotSatisfiable`, `ExpectationFailed`, `MisdirectedRequest`, `UnprocessableEntity`, `Locked`, `FailedDependency`, `UpgradeRequired`, `PreconditionRequired`, `TooManyRequests`, `RequestHeaderFieldsTooLarge`, `UnavailableForLegalReasons`, `InternalServerError`, `NotImplemented`, `BadGateway`, `ServiceUnavailable`, `GatewayTimeout`, `HttpVersionNotSupported`, `VariantAlsoNegotiates`, `InsufficientStorage`, `LoopDetected`, `NotExtended`, `NetworkAuthenticationRequired`
- `data` (ApiKeyDto, optional) — Represents api access key entity

## Types

### AstroError

Information about an error that occurred within the ProjectManager API.

- `technicalError` (string, optional, nullable) — A technical description of the error that occurred. Not suitable for display to end users.
- `additionalErrors` (list of string, optional, nullable) — If additional errors beyond the main error in `Message` occurred, they will be listed here as individual messages.
- `validationErrors` (map from string to list of string, optional, nullable) — This contains a dictionary of validation errors. The key is the name of the field
- `message` (string, optional, nullable) — A description of the error that occurred. If your application has a user interface, show this message to explain what went wrong.

### ApiKeyDto

Represents api access key entity

- `id` (string, optional) — Internal access token id
- `createdBy` (string, optional) — Created by user id
- `expires` (string, optional) — Expires date
- `apiKey` (string, optional) — Bearer Key
- `name` (string, optional) — Name of token

## Examples

**Request**

```json
{
  "tokenName": "string"
}
```

**Response**

```json
{
  "error": {
    "technicalError": "string",
    "additionalErrors": [
      "string"
    ],
    "validationErrors": {},
    "message": "string"
  },
  "success": true,
  "hasError": true,
  "statusCode": "Continue",
  "data": {
    "id": "string",
    "createdBy": "string",
    "expires": "2024-01-15T09:30:00Z",
    "apiKey": "string",
    "name": "string"
  }
}
```

**SDK Code**

```python
import requests

url = "https://api.projectmanager.com/api/data/api-keys"

payload = { "tokenName": "string" }
headers = {
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript
const url = 'https://api.projectmanager.com/api/data/api-keys';
const options = {
  method: 'POST',
  headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
  body: '{"tokenName":"string"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.projectmanager.com/api/data/api-keys"

	payload := strings.NewReader("{\n  \"tokenName\": \"string\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://api.projectmanager.com/api/data/api-keys")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"tokenName\": \"string\"\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.projectmanager.com/api/data/api-keys")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"tokenName\": \"string\"\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.projectmanager.com/api/data/api-keys', [
  'body' => '{
  "tokenName": "string"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp
using RestSharp;

var client = new RestClient("https://api.projectmanager.com/api/data/api-keys");
var request = new RestRequest(Method.POST);
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"tokenName\": \"string\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let headers = [
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = ["tokenName": "string"] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.projectmanager.com/api/data/api-keys")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```