> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Api Key

> API Key management



## OpenAPI

````yaml api-reference/speakeasy/textql-api-with-code-samples.yaml POST /textql.rpc.public.rbac.RBACService/CreateApiKey
openapi: 3.1.0
info:
  title: TextQL API
  version: 1.0.0
  description: |
    TextQL public API. Generated from protobuf service definitions; internal
    endpoints are excluded via google.api.visibility / file_visibility.
servers:
  - url: https://app.textql.com
security:
  - apiKey: []
tags:
  - name: DashboardService
  - name: AppService
    description: |-
      AppService manages data apps: the generative app execution primitive.
       An app is agent-authored single-file HTML/JS/CSS executing in a CSP sandbox,
       fed a snapshot of its declared data sources. First-class resource, not a dashboard.
  - name: ConnectorService
  - name: PowerBIService
  - name: TableauService
  - name: DatasetService
  - name: OntologyManagementService
  - name: ChatService
  - name: AgentService
  - name: AuditLogService
  - name: MCPService
  - name: MetricsExportService
  - name: ObservabilityService
  - name: PlaybookService
  - name: RBACService
    description: RBAC service for managing roles, permissions, and access control
  - name: SandboxAdminService
  - name: SandboxQueryService
  - name: SandboxCapabilityService
  - name: ScimService
  - name: SecretService
  - name: SlackService
  - name: TeamsService
paths:
  /textql.rpc.public.rbac.RBACService/CreateApiKey:
    post:
      tags:
        - RBACService
      summary: API Key management
      description: API Key management
      operationId: RBACService_CreateApiKey
      parameters:
        - name: Connect-Protocol-Version
          in: header
          required: true
          schema:
            $ref: '#/components/schemas/connect-protocol-version'
        - name: Connect-Timeout-Ms
          in: header
          schema:
            $ref: '#/components/schemas/connect-timeout-header'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/textql.rpc.public.rbac.CreateApiKeyRequest'
        required: true
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/textql.rpc.public.rbac.CreateApiKeyResponse
        default:
          description: Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/connect.error'
      x-codeSamples:
        - lang: python
          label: Python (SDK)
          source: |-
            import os
            from textql_sdk import Textql


            with Textql(
                api_key=os.getenv("TEXTQL_API_KEY", ""),
            ) as textql:

                res = textql.rbac.create_api_key()

                # Handle response
                print(res)
        - lang: typescript
          label: TypeScript (SDK)
          source: |-
            import { Textql } from "@textql/sdk";

            const textql = new Textql({
              apiKey: process.env["TEXTQL_API_KEY"] ?? "",
            });

            async function run() {
              const result = await textql.rbac.createApiKey({
                body: {},
              });

              console.log(result);
            }

            run();
components:
  schemas:
    connect-protocol-version:
      type: number
      title: Connect-Protocol-Version
      enum:
        - 1
      description: Define the version of the Connect protocol
      const: 1
      default: 1
    connect-timeout-header:
      type: number
      title: Connect-Timeout-Ms
      description: Define the timeout, in ms
    textql.rpc.public.rbac.CreateApiKeyRequest:
      type: object
      properties:
        expirySeconds:
          type: integer
          title: expiry_seconds
          nullable: true
        assumedRoles:
          type: array
          items:
            type: string
          title: assumed_roles
          description: >-
            Role IDs (UUIDs) to scope the new API key to. The service validates
            that
             each ID exists in the caller's org. Non-admin callers may only specify
             roles they already hold; assumed-role API key callers may only specify
             a subset of their current assumed roles.
        inheritAllRoles:
          type: boolean
          title: inherit_all_roles
          description: |-
            When true, the API key inherits all of the creating member's roles
             (no assumed-role scoping). Callers must set this explicitly when
             assumed_roles is empty; otherwise the request is rejected to prevent
             accidentally creating over-privileged keys.
          nullable: true
        name:
          type: string
          title: name
          description: Optional display name for the API key.
          nullable: true
        targetMemberId:
          type: string
          title: target_member_id
          description: |-
            Optional owner override for the new API key.
             If unset, the API key is created for the calling member.
             If set, the API key is created for this member ID (target principal):
             service-account targets require the caller to hold organization:write;
             human targets require api_access_key:delegate, and the key is bounded
             by the target member's roles with superadmin elevation always
             suppressed.
          nullable: true
        clientId:
          type: string
          title: client_id
          description: |-
            Optional client metadata stored on the API key as client_id.
             Prefer a JSON object string when using structured client attributes.
          nullable: true
        suppressSuperadmin:
          type: boolean
          title: suppress_superadmin
          description: |-
            When true, requests authenticated with this key skip the
             @textql.com-email superadmin elevation branch. Only meaningful
             when paired with assumed_roles so a textql admin can preview a
             role's experience without superadmin permissions bleeding through.
      title: CreateApiKeyRequest
      additionalProperties: false
    textql.rpc.public.rbac.CreateApiKeyResponse:
      type: object
      properties:
        apiKey:
          $ref: '#/components/schemas/textql.rpc.public.rbac.ApiKey'
          title: api_key
        apiKeySecret:
          type: string
          title: api_key_secret
        apiKeyHash:
          type: string
          title: api_key_hash
          description: >-
            Deprecated compatibility alias for api_key_secret. This field
            contains
             the same one-time bearer credential; it is not the hash stored at rest.
          deprecated: true
      title: CreateApiKeyResponse
      additionalProperties: false
    connect.error:
      type: object
      properties:
        code:
          type: string
          examples:
            - not_found
          enum:
            - canceled
            - unknown
            - invalid_argument
            - deadline_exceeded
            - not_found
            - already_exists
            - permission_denied
            - resource_exhausted
            - failed_precondition
            - aborted
            - out_of_range
            - unimplemented
            - internal
            - unavailable
            - data_loss
            - unauthenticated
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/connect.error_details.Any'
          description: >-
            A list of messages that carry the error details. There is no limit
            on the number of messages.
      title: Connect Error
      additionalProperties: true
      description: >-
        Error type returned by Connect:
        https://connectrpc.com/docs/go/errors/#http-representation
    textql.rpc.public.rbac.ApiKey:
      type: object
      properties:
        id:
          type: string
          title: id
        memberId:
          type: string
          title: member_id
        clientId:
          type: string
          title: client_id
        createdAt:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
          title: created_at
        apiKeyShort:
          type: string
          title: api_key_short
          nullable: true
        assumedRoles:
          type: array
          items:
            type: string
          title: assumed_roles
          description: >-
            Role IDs (UUIDs) that this API key is scoped to. When set,
            authorization
             is evaluated strictly against these roles. Returned as role IDs; use the
             Role service (GetRole/ListRoles) to resolve to human-readable names.
        name:
          type: string
          title: name
          nullable: true
        expiresAt:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
          title: expires_at
          nullable: true
        revokedAt:
          $ref: '#/components/schemas/google.protobuf.Timestamp'
          title: revoked_at
          nullable: true
        status:
          $ref: '#/components/schemas/textql.rpc.public.rbac.ApiKeyStatus'
          title: status
        ownerDisplayName:
          type: string
          title: owner_display_name
          nullable: true
        ownerEmail:
          type: string
          title: owner_email
          nullable: true
        suppressSuperadmin:
          type: boolean
          title: suppress_superadmin
          description: |-
            When true, requests authenticated with this key skip the
             @textql.com-email superadmin elevation branch. Lets a textql admin
             preview a role's experience without superadmin permission leakage.
      title: ApiKey
      additionalProperties: false
    connect.error_details.Any:
      type: object
      properties:
        type:
          type: string
          description: >-
            A URL that acts as a globally unique identifier for the type of the
            serialized message. For example:
            `type.googleapis.com/google.rpc.ErrorInfo`. This is used to
            determine the schema of the data in the `value` field and is the
            discriminator for the `debug` field.
        value:
          type: string
          format: binary
          description: >-
            The Protobuf message, serialized as bytes and base64-encoded. The
            specific message type is identified by the `type` field.
        debug:
          oneOf:
            - type: object
              title: Any
              additionalProperties: true
              description: Detailed error information.
          discriminator:
            propertyName: type
          title: Debug
          description: >-
            Deserialized error detail payload. The 'type' field indicates the
            schema. This field is for easier debugging and should not be relied
            upon for application logic.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message, with an additional debug
        field for ConnectRPC error details.
    google.protobuf.Timestamp:
      type: string
      examples:
        - '2023-01-15T01:30:15.01Z'
        - '2024-12-25T12:00:00Z'
      format: date-time
      description: >-
        A Timestamp represents a point in time independent of any time zone or
        local
         calendar, encoded as a count of seconds and fractions of seconds at
         nanosecond resolution. The count is relative to an epoch at UTC midnight on
         January 1, 1970, in the proleptic Gregorian calendar which extends the
         Gregorian calendar backwards to year one.

         All minutes are 60 seconds long. Leap seconds are "smeared" so that no leap
         second table is needed for interpretation, using a [24-hour linear
         smear](https://developers.google.com/time/smear).

         The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By
         restricting to that range, we ensure that we can convert to and from [RFC
         3339](https://www.ietf.org/rfc/rfc3339.txt) date strings.

         # Examples

         Example 1: Compute Timestamp from POSIX `time()`.

             Timestamp timestamp;
             timestamp.set_seconds(time(NULL));
             timestamp.set_nanos(0);

         Example 2: Compute Timestamp from POSIX `gettimeofday()`.

             struct timeval tv;
             gettimeofday(&tv, NULL);

             Timestamp timestamp;
             timestamp.set_seconds(tv.tv_sec);
             timestamp.set_nanos(tv.tv_usec * 1000);

         Example 3: Compute Timestamp from Win32 `GetSystemTimeAsFileTime()`.

             FILETIME ft;
             GetSystemTimeAsFileTime(&ft);
             UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;

             // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z
             // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.
             Timestamp timestamp;
             timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));
             timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));

         Example 4: Compute Timestamp from Java `System.currentTimeMillis()`.

             long millis = System.currentTimeMillis();

             Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)
                 .setNanos((int) ((millis % 1000) * 1000000)).build();

         Example 5: Compute Timestamp from Java `Instant.now()`.

             Instant now = Instant.now();

             Timestamp timestamp =
                 Timestamp.newBuilder().setSeconds(now.getEpochSecond())
                     .setNanos(now.getNano()).build();

         Example 6: Compute Timestamp from current time in Python.

             timestamp = Timestamp()
             timestamp.GetCurrentTime()

         # JSON Mapping

         In JSON format, the Timestamp type is encoded as a string in the
         [RFC 3339](https://www.ietf.org/rfc/rfc3339.txt) format. That is, the
         format is "{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z"
         where {year} is always expressed using four digits while {month}, {day},
         {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional
         seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution),
         are optional. The "Z" suffix indicates the timezone ("UTC"); the timezone
         is required. A proto3 JSON serializer should always use UTC (as indicated by
         "Z") when printing the Timestamp type and a proto3 JSON parser should be
         able to accept both UTC and other timezones (as indicated by an offset).

         For example, "2017-01-15T01:30:15.01Z" encodes 15.01 seconds past
         01:30 UTC on January 15, 2017.

         In JavaScript, one can convert a Date object to this format using the
         standard
         [toISOString()](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/toISOString)
         method. In Python, a standard `datetime.datetime` object can be converted
         to this format using
         [`strftime`](https://docs.python.org/2/library/time.html#time.strftime) with
         the time format spec '%Y-%m-%dT%H:%M:%S.%fZ'. Likewise, in Java, one can use
         the Joda Time's [`ISODateTimeFormat.dateTime()`](
         http://joda-time.sourceforge.net/apidocs/org/joda/time/format/ISODateTimeFormat.html#dateTime()
         ) to obtain a formatter capable of generating timestamps in this format.
    textql.rpc.public.rbac.ApiKeyStatus:
      type: string
      title: ApiKeyStatus
      enum:
        - API_KEY_STATUS_UNSPECIFIED
        - API_KEY_STATUS_ACTIVE
        - API_KEY_STATUS_EXPIRED
        - API_KEY_STATUS_REVOKED
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: tql_api_key

````