Create a key
Mints a Median key pair: the secret root for MEDIAN_KEY, and the browser-safe publishable half the widget ships with. Returned in full exactly once; the database keeps fingerprints. The first key an organization mints also retires any legacy credentials.
POST
/keysAuthorization
AuthorizationBearer token · headerrequired`MEDIAN_KEY` from Settings under API, or an MCP OAuth access token. A key acts as the organization; a token acts as the person who approved it.
Request body
application/jsonnamestringmax length 40
Responses
200The pair, shown once. Store both now.
idstringkeystringpublicKeystring400The request is malformed, and the message names the field.
errorobjectShow propertiesHide properties
codestringmessagestring401The bearer token is missing, revoked, or expired.
errorobjectShow propertiesHide properties
codestringmessagestring403The token's person does not hold the role this needs.
errorobjectShow propertiesHide properties
codestringmessagestring429Too many requests. Wait the seconds in `Retry-After`. Limits depend on the plan. See [rate limits](/api/errors-and-limits#rate-limits).
errorobjectShow propertiesHide properties
codestringmessagestringRequest
curl -X POST "https://api.median.sh/v1/keys" \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "production"
}'const response = await fetch("https://api.median.sh/v1/keys", {
method: "POST",
headers: {
"Authorization": "Bearer YOUR_TOKEN",
"Content-Type": "application/json"
},
body: JSON.stringify({
"name": "production"
})
});Response
{
"id": "string",
"key": "string",
"publicKey": "string"
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}{
"error": {
"code": "string",
"message": "string"
}
}