Create website key
POST https://datafa.st/api/v1/admin/websites/{websiteId}/apikeysCreate a new
df_ website API key. The full key is returned once — store it securely. Maximum 10 keys per website.Use website keys for single-site integrations that should not manage the broader account.
Request
Path parameters
websiteIdstring
Body parameters
namestring
Label for the API key in the dashboard. Example:
"Production backend". Omit for null.Example request body
{
"name": "Production backend"
}
The response includes
key once — store it as df_... for Website API calls.Response
Returns a JSON object with
status: "success" and endpoint-specific fields in data.Response fields
data[].idstring
Website API key ObjectId.
data[].userIdstring
User ObjectId that owns the key.
data[].namestring|null
Human-readable name for the resource or event. The exact meaning depends on the endpoint.
data[].displayKeystring
Masked key shown in the dashboard.
data[].websiteIdstring
Website ObjectId used by account tokens to choose which website to query or manage.
data[].keyPrefixstring
Indexed key prefix used for lookup.
data[].lastUsedAtstring|null
Last usage timestamp.
data[].usageCountnumber
Number of authenticated uses.
data[].isMobileboolean
Whether the key was created for the mobile app. Mobile keys are excluded from list responses.
data[].createdAtstring
Creation timestamp.
data[].updatedAtstring
Last update timestamp.
data[].keystring
Only returned when creating or rolling a key. Full raw key shown once.
Authentication
Use a
dft_ account token with api-keys:write.A
df_ website API key for the same website can also call this route when the path websiteId matches the key's website. Write access with a df_ key is capped at member level — owner-only actions such as team management require a dft_ token and owner role.Errors
400 — Key limit reached (max 10 per website).
See API errors for the standard error envelope, auth failures, validation errors, permission errors, and rate limits.