# Create an API key

**POST** `/admin/projects/{project_id}/api-keys`

:::code-group
```bash title="cURL"
curl --request POST \
  --url https://api.pinecone.io/admin/projects/{project_id}/api-keys \
  --header 'Authorization: Bearer <token>' \
  --header 'X-Pinecone-Api-Version: <x-pinecone-api-version>' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "devkey",
  "roles": [
    "ProjectEditor"
  ]
}'
```

```python title="Python"
import requests

url = "https://api.pinecone.io/admin/projects/{project_id}/api-keys"

payload = {
  "name": "devkey",
  "roles": [
    "ProjectEditor"
  ]
}
headers = {
    "Authorization": "Bearer <token>",
    "X-Pinecone-Api-Version": "<x-pinecone-api-version>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.text)
```

```javascript title="JavaScript"
const options = {method: "POST", headers: {"Authorization": "Bearer <token>", "X-Pinecone-Api-Version": "<x-pinecone-api-version>", "Content-Type": "application/json"}, body: JSON.stringify({
  "name": "devkey",
  "roles": [
    "ProjectEditor"
  ]
})};

fetch("https://api.pinecone.io/admin/projects/{project_id}/api-keys", options)
  .then(res => res.json())
  .then(res => console.log(res))
  .catch(err => console.error(err));
```

```php title="PHP"
<?php

$curl = curl_init();

curl_setopt_array($curl, [
  CURLOPT_URL => "https://api.pinecone.io/admin/projects/{project_id}/api-keys",
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_CUSTOMREQUEST => "POST",
  CURLOPT_POSTFIELDS => "{\"name\":\"devkey\",\"roles\":[\"ProjectEditor\"]}",
  CURLOPT_HTTPHEADER => [
    "Authorization: Bearer <token>",
    "X-Pinecone-Api-Version: <x-pinecone-api-version>",
    "Content-Type: application/json"
  ],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
  echo "cURL Error #:" . $err;
} else {
  echo $response;
}
```

```go title="Go"
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.pinecone.io/admin/projects/{project_id}/api-keys"

	payload := strings.NewReader("{\"name\":\"devkey\",\"roles\":[\"ProjectEditor\"]}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(string(body))

}
```

```java title="Java"
HttpResponse<String> response = Unirest.post("https://api.pinecone.io/admin/projects/{project_id}/api-keys")
  .header("Authorization", "Bearer <token>")
  .header("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
  .header("Content-Type", "application/json")
  .body("{\"name\":\"devkey\",\"roles\":[\"ProjectEditor\"]}")
  .asString();
```

```ruby title="Ruby"
require 'uri'
require 'net/http'

url = URI("https://api.pinecone.io/admin/projects/{project_id}/api-keys")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Pinecone-Api-Version"] = '<x-pinecone-api-version>'
request["Content-Type"] = 'application/json'
request.body = "{\"name\":\"devkey\",\"roles\":[\"ProjectEditor\"]}"

response = http.request(request)
puts response.read_body
```
:::

:::code-group
```json title="201"
{
  "key": {
    "id": "<string>",
    "name": "<string>",
    "project_id": "<string>",
    "roles": [
      "ProjectEditor"
    ]
  },
  "value": "<string>"
}
```

```json title="400"
{
  "error": {
    "code": "INVALID_ARGUMENT",
    "message": "Bad request. The request body included invalid request parameters."
  },
  "status": 400
}
```

```json title="401"
{
  "error": {
    "code": "UNAUTHENTICATED",
    "message": "Invalid API key."
  },
  "status": 401
}
```

```json title="403"
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
```

```json title="500"
{
  "error": {
    "code": "UNKNOWN",
    "message": "Internal server error"
  },
  "status": 500
}
```

```json title="4XX"
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
```
:::

#### Authorizations

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `Authorization` | `string` | - |  |

An [access token](/guides/admin-organizations-manage-service-accounts#retrieve-an-access-token) must be provided in the `Authorization` header using the `Bearer` scheme.

#### Headers

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `X-Pinecone-Api-Version` | `string` | `2026-07` | Required date-based version header |

#### Path Parameters

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `project_id` | `string` | - | Project ID |

#### Body

The details of the new API key.

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `name` | `string` | - | The name of the API key. The name must be 1-80 characters long. Required string length: 1 - 80. Example: devkey |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `roles?` | `string[]` | - | The roles to create the API key with. Default is ['ProjectEditor']. |

#### Response

`201` — API key created successfully.

The details of an API key, including the secret. Only returned on API key creation.

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `key` | `object` | - | The details of an API key, without the secret. |

:::accordion{title="Show child attributes"}
| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `id` | `string` | - | The unique ID of the API key. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `name` | `string` | - | The name of the API key. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `project_id` | `string` | - | The ID of the project containing the API key. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `roles` | `string[]` | - | The roles assigned to the API key. |
:::

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `value` | `string` | - |  |

The value to use as an API key. New keys will have the format `"pckey_<public-label>_<unique-key>"`. The entire string should be used when authenticating.

## Related pages

- [List API keys](./admin-2-api-keys-list-api-keys.md)
- [Get API key details](./admin-2-api-keys-get-api-key-details.md)
- [Delete an API key](./admin-2-api-keys-delete-an-api-key.md)
- [Update an API key](./admin-2-api-keys-update-an-api-key.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
