Skip to main content
Pinecone Docs
current

Search documentation

Type to search this documentation.

Create an API key

Create an API key for a project to authenticate Data Plane and Control Plane requests.

POST/admin/projects/{project_id}/api-keys

Create an API key

2 parameters
  • X-Pinecone-Api-Versionstringheaderrequired

    Required date-based version header

  • project_idstringpathrequired

    Project ID

cURL
curl --request POST \
  --url https://api.pinecone.io/admin/projects/{project_id}/api-keys \
  --header 'Authorization: Bearer <token>' \
  --header 'X-Pinecone-Api-Version: <x-pinecone-api-version>' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "devkey",
  "roles": [
    "ProjectEditor"
  ]
}'
Python
import requests

url = "https://api.pinecone.io/admin/projects/{project_id}/api-keys"

payload = {
  "name": "devkey",
  "roles": [
    "ProjectEditor"
  ]
}
headers = {
    "Authorization": "Bearer <token>",
    "X-Pinecone-Api-Version": "<x-pinecone-api-version>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.text)
JavaScript
const options = {method: "POST", headers: {"Authorization": "Bearer <token>", "X-Pinecone-Api-Version": "<x-pinecone-api-version>", "Content-Type": "application/json"}, body: JSON.stringify({
  "name": "devkey",
  "roles": [
    "ProjectEditor"
  ]
})};

fetch("https://api.pinecone.io/admin/projects/{project_id}/api-keys", options)
  .then(res => res.json())
  .then(res => console.log(res))
  .catch(err => console.error(err));
PHP
<?php

$curl = curl_init();

curl_setopt_array($curl, [
  CURLOPT_URL => "https://api.pinecone.io/admin/projects/{project_id}/api-keys",
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_CUSTOMREQUEST => "POST",
  CURLOPT_POSTFIELDS => "{\"name\":\"devkey\",\"roles\":[\"ProjectEditor\"]}",
  CURLOPT_HTTPHEADER => [
    "Authorization: Bearer <token>",
    "X-Pinecone-Api-Version: <x-pinecone-api-version>",
    "Content-Type: application/json"
  ],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
  echo "cURL Error #:" . $err;
} else {
  echo $response;
}
Go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.pinecone.io/admin/projects/{project_id}/api-keys"

	payload := strings.NewReader("{\"name\":\"devkey\",\"roles\":[\"ProjectEditor\"]}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(string(body))

}
Java
HttpResponse<String> response = Unirest.post("https://api.pinecone.io/admin/projects/{project_id}/api-keys")
  .header("Authorization", "Bearer <token>")
  .header("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
  .header("Content-Type", "application/json")
  .body("{\"name\":\"devkey\",\"roles\":[\"ProjectEditor\"]}")
  .asString();
Ruby
require 'uri'
require 'net/http'

url = URI("https://api.pinecone.io/admin/projects/{project_id}/api-keys")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Pinecone-Api-Version"] = '<x-pinecone-api-version>'
request["Content-Type"] = 'application/json'
request.body = "{\"name\":\"devkey\",\"roles\":[\"ProjectEditor\"]}"

response = http.request(request)
puts response.read_body
201
{
  "key": {
    "id": "<string>",
    "name": "<string>",
    "project_id": "<string>",
    "roles": [
      "ProjectEditor"
    ]
  },
  "value": "<string>"
}
400
{
  "error": {
    "code": "INVALID_ARGUMENT",
    "message": "Bad request. The request body included invalid request parameters."
  },
  "status": 400
}
401
{
  "error": {
    "code": "UNAUTHENTICATED",
    "message": "Invalid API key."
  },
  "status": 401
}
403
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
500
{
  "error": {
    "code": "UNKNOWN",
    "message": "Internal server error"
  },
  "status": 500
}
4XX
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
Authorizationstringrequired

An access token must be provided in the Authorization header using the Bearer scheme.

X-Pinecone-Api-Versionstringrequired

Required date-based version header

Typestring
Default2026-07
project_idstringrequired

Project ID

Typestring

The details of the new API key.

namestringrequired

The name of the API key. The name must be 1-80 characters long.

Required string length: 1 - 80. Example: devkey

Typestring
roles?string[]

The roles to create the API key with. Default is ['ProjectEditor'].

Typestring[]

201 — API key created successfully.

The details of an API key, including the secret. Only returned on API key creation.

keyobjectrequired

The details of an API key, without the secret.

Typeobject
Show child attributes
idstringrequired

The unique ID of the API key.

Typestring
namestringrequired

The name of the API key.

Typestring
project_idstringrequired

The ID of the project containing the API key.

Typestring
rolesstring[]required

The roles assigned to the API key.

Typestring[]
valuestringrequired

The value to use as an API key. New keys will have the format "pckey_<public-label>_<unique-key>". The entire string should be used when authenticating.

Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu