Skip to main content
POST
Create API key

Authorizations

Authorization
string
header
required

JWT token authentication

Headers

NexSpace-Version
string

Pin the request to a dated API version (e.g. 2026-05-10). Applied by app-level middleware to every /api route (server/routes/index.ts → apiVersionMiddleware), which echoes the resolved value back in the NexSpace-Version response header. Omit to get the latest version. Discover the catalog at GET /.well-known/api-versions.

Pattern: ^\d{4}-\d{2}-\d{2}$
Idempotency-Key
string

Replay guard for write requests. Applied by app-level middleware to every /api route (server/routes/index.ts → idempotencyMiddleware), which only acts on POST/PUT/PATCH — GET, DELETE and OPTIONS ignore the header. Re-sending the same key with an identical body within 24 hours replays the original response; the same key with a different body returns 409.

Maximum string length: 255

Body

application/json
name
string
required

Human-readable key name

Required string length: 1 - 120
scopes
enum<string>[]
required

Granted permission scopes. The enum is the canonical catalog (HEADLESS_KNOWN_SCOPES in shared/headless-scopes.ts) — the only scopes that gate real surface. The server's own validator is looser (it accepts any resource:action string matching ^[a-z_]+:[a-z*]+$, so wildcards such as shifts:* are stored), but a scope outside this catalog grants nothing on the headless surface. Authorization matches on exact scope, resource:*, or *.

Minimum array length: 1
Available options:
shifts:read,
shifts:write,
shifts:assign,
staff:read,
staff:write,
credentials:read,
credentials:verify,
payroll:read,
payroll:run,
crm:*,
facilities:read,
facilities:write,
integrations:write,
analytics:read,
facility:read,
calendar:read,
communications:read,
marketing:read,
general:read,
scheduling:read,
crm:read,
compliance:read,
crm:write,
scheduling:write,
communications:write,
apps:read,
apps:write,
agents:run,
agents:approve
Example:
expiresAt
string<date-time>

Optional expiry timestamp

ipAllowlist
string[]

Optional IPv4/IPv6 CIDR allowlist

rateLimitPerMin
integer
default:60
Required range: 1 <= x <= 6000
asPat
boolean
default:false

Mint as personal access token (nex_pat_ prefix)

Response

API key created (plaintext token in key field — display once)

id
integer
name
string
prefix
string

Token prefix (e.g. nex_live_, nex_test_, nex_pat_)

lastFour
string

Last 4 characters of the token

scopes
string[]
facilityId
integer | null
ipAllowlist
string[]
rateLimitPerMin
integer
lastUsedAt
string<date-time> | null
expiresAt
string<date-time> | null
revokedAt
string<date-time> | null
rotationGraceUntil
string<date-time> | null
createdAt
string<date-time>
key
string

Plaintext token — store securely, never shown again