Create an API key
Requires api_keys:write. Returns the key in plaintext — the only time it is ever readable. A lost key is replaced, never recovered.
A key is born in an environment and never leaves it: the environment is chosen here, minted into the prefix (uk_sk_live_… / uk_sk_test_…), and resolved from the stored row on every request — never from anything the caller sends later.
Autorizações
A staff session token, uk_st_…. Minted by sign-up, sign-in or the two-factor exchange.
Cabeçalhos
The organization the caller is acting on — the org_… code that appears in the panel URL. It identifies; the membership JOIN is what authorizes, so a forged code reads nothing. Absent, the session's default organization answers.