:::code-group
```javascript JavaScript theme={null}
// Requires Node.js SDK v8.2.0 or later
import { AdminClient } from '@pinecone-database/pinecone';

// Reads PINECONE_CLIENT_ID and PINECONE_CLIENT_SECRET from the environment
const admin = new AdminClient();

const apiKey = await admin.apiKeys.create('YOUR_PROJECT_ID', {
  name: 'Example API Key',
  roles: ['ProjectEditor'],
});

// `apiKey.value` is returned only at creation time and cannot be retrieved
// later. Store it securely and never log it.
console.log(apiKey.key);
```

```go Go theme={null}
// Requires Go SDK v6.0.0 or later
package main

import (
    "context"
    "fmt"
    "log"
    "os"

    "github.com/pinecone-io/go-pinecone/v6/pinecone"
)

func main() {
    ctx := context.Background()

    adminClient, err := pinecone.NewAdminClientWithContext(ctx, pinecone.NewAdminClientParams{
        ClientId:     os.Getenv("PINECONE_CLIENT_ID"),
        ClientSecret: os.Getenv("PINECONE_CLIENT_SECRET"),
    })
    if err != nil {
        log.Fatalf("Failed to create AdminClient: %v", err)
    }

    roles := []string{"ProjectEditor"}
    apiKey, err := adminClient.APIKey.Create(ctx, "YOUR_PROJECT_ID", &pinecone.CreateAPIKeyParams{
        Name:  "Example API Key",
        Roles: &roles,
    })
    if err != nil {
        log.Fatalf("Failed to create API key: %v", err)
    }
    // Value is returned only at creation time — store it securely and never log it
    fmt.Printf("Successfully created API key: %v\n", apiKey.Key.Id)
}
```

```hcl Terraform theme={null}
# Requires Terraform provider v4.0.0 or later
resource "pinecone_api_key" "example" {
  name       = "Example API Key"
  project_id = "YOUR_PROJECT_ID"
  roles      = ["ProjectEditor"]
}
```

```bash curl theme={null}
PINECONE_ACCESS_TOKEN="YOUR_ACCESS_TOKEN"
PINECONE_PROJECT_ID="YOUR_PROJECT_ID"

curl "https://api.pinecone.io/admin/projects/$PINECONE_PROJECT_ID/api-keys" \
	-H "X-Pinecone-Api-Version: 2026-04" \
	-H "Authorization: Bearer $PINECONE_ACCESS_TOKEN" \
	-d '{
		"name": "Example API Key",
		"roles": ["ProjectEditor"]
	}'
```
:::

:::code-group
```json curl theme={null}
{
  "key": {
    "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "name": "Example API key",
    "project_id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "roles": [
      "ProjectEditor"
    ]
  },
  "value": "string"
}
```
:::

**POST** `/admin/projects/{project_id}/api-keys`

#### Authorizations

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `Authorization` | `string` | - |  |

An [access token](/guides/admin-organizations-manage-service-accounts#retrieve-an-access-token) must be provided in the `Authorization` header using the `Bearer` scheme.

#### Headers

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `X-Pinecone-Api-Version` | `string` | `2026-04` | Required date-based version header |

#### Path Parameters

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `project_id` | `string` | - | Project ID |

#### Body

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `name` | `string` | - | The name of the API key. The name must be 1-80 characters long. Required string length: 1 - 80. Example: devkey |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `roles?` | `string[]` | - | The roles to create the API key with. Default is ['ProjectEditor']. |

#### Response

`201` — API key created successfully.

The details of an API key, including the secret. Only returned on API key creation.

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `key` | `object` | - | The details of an API key, without the secret. |

:::accordion{title="Show child attributes"}
| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `id` | `string` | - | The unique ID of the API key. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `name` | `string` | - | The name of the API key. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `project_id` | `string` | - | The ID of the project containing the API key. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `roles` | `string[]` | - | The roles assigned to the API key. |
:::

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `value` | `string` | - |  |

The value to use as an API key. New keys will have the format `"pckey_<public-label>_<unique-key>"`. The entire string should be used when authenticating.

## Related pages

- [List API keys](./admin-2-2026-07-admin-api-keys-list-api-keys.md)
- [Create an API key](./admin-2-2026-07-admin-api-keys-create-an-api-key.md)
- [Get API key details](./admin-2-2026-07-admin-api-keys-get-api-key-details.md)
- [Delete an API key](./admin-2-2026-07-admin-api-keys-delete-an-api-key.md)
- [Update an API key](./admin-2-2026-07-admin-api-keys-update-an-api-key.md)
- [Create an API key](./admin-2-2026-04-admin-assistant-create-api-key.md)
- [List API keys](./admin-2-2026-04-admin-assistant-list-api-keys.md)
- [Get API key details](./admin-2-2026-04-admin-assistant-fetch-api-key.md)
- [Update an API key](./admin-2-2026-04-admin-assistant-update-api-key.md)
- [Delete an API key](./admin-2-2026-04-admin-assistant-delete-api-key.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
