curl --request POST \
--url https://brew.new/api/v1/api-keys \
--header 'Content-Type: application/json' \
--cookie __session= \
--data '
{
"name": "CI",
"permissions": [
"emails",
"domains"
],
"brandId": "kx7b3s7fapqz8mjm12ekz1kxdx87yceg"
}
'import requests
url = "https://brew.new/api/v1/api-keys"
payload = {
"name": "CI",
"permissions": ["emails", "domains"],
"brandId": "kx7b3s7fapqz8mjm12ekz1kxdx87yceg"
}
headers = {
"cookie": "__session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {cookie: '__session=', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'CI',
permissions: ['emails', 'domains'],
brandId: 'kx7b3s7fapqz8mjm12ekz1kxdx87yceg'
})
};
fetch('https://brew.new/api/v1/api-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://brew.new/api/v1/api-keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'CI',
'permissions' => [
'emails',
'domains'
],
'brandId' => 'kx7b3s7fapqz8mjm12ekz1kxdx87yceg'
]),
CURLOPT_COOKIE => "__session=",
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://brew.new/api/v1/api-keys"
payload := strings.NewReader("{\n \"name\": \"CI\",\n \"permissions\": [\n \"emails\",\n \"domains\"\n ],\n \"brandId\": \"kx7b3s7fapqz8mjm12ekz1kxdx87yceg\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("cookie", "__session=")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://brew.new/api/v1/api-keys")
.header("cookie", "__session=")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"CI\",\n \"permissions\": [\n \"emails\",\n \"domains\"\n ],\n \"brandId\": \"kx7b3s7fapqz8mjm12ekz1kxdx87yceg\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://brew.new/api/v1/api-keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["cookie"] = '__session='
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"CI\",\n \"permissions\": [\n \"emails\",\n \"domains\"\n ],\n \"brandId\": \"kx7b3s7fapqz8mjm12ekz1kxdx87yceg\"\n}"
response = http.request(request)
puts response.read_body{
"key": "brew_abcdefghijklmnopqrstuvwxyz012345",
"keyId": "kd7b3s7fapqz8mjm12ekz1kxdx87yceg",
"message": "Save this key securely. You won't be able to see it again."
}Create an API key
Mints a new API key through an exact org:admin Clerk session; API-key and OAuth actors receive 403. The plaintext key is returned once and only its hash plus final preview are stored. This operation intentionally does not support response replay or Idempotency-Key, because replay would disclose the credential again. brandId in the body is the NEW KEY’s binding (omit for an organization-wide key) — the only v1 body field named brandId. Permissions default to ["all"]. To rotate without downtime, send only replacesKeyId; Brew copies the active predecessor’s name, scope, and permissions and leaves it active until you revoke it after switching consumers.
curl --request POST \
--url https://brew.new/api/v1/api-keys \
--header 'Content-Type: application/json' \
--cookie __session= \
--data '
{
"name": "CI",
"permissions": [
"emails",
"domains"
],
"brandId": "kx7b3s7fapqz8mjm12ekz1kxdx87yceg"
}
'import requests
url = "https://brew.new/api/v1/api-keys"
payload = {
"name": "CI",
"permissions": ["emails", "domains"],
"brandId": "kx7b3s7fapqz8mjm12ekz1kxdx87yceg"
}
headers = {
"cookie": "__session=",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {cookie: '__session=', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'CI',
permissions: ['emails', 'domains'],
brandId: 'kx7b3s7fapqz8mjm12ekz1kxdx87yceg'
})
};
fetch('https://brew.new/api/v1/api-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://brew.new/api/v1/api-keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'CI',
'permissions' => [
'emails',
'domains'
],
'brandId' => 'kx7b3s7fapqz8mjm12ekz1kxdx87yceg'
]),
CURLOPT_COOKIE => "__session=",
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://brew.new/api/v1/api-keys"
payload := strings.NewReader("{\n \"name\": \"CI\",\n \"permissions\": [\n \"emails\",\n \"domains\"\n ],\n \"brandId\": \"kx7b3s7fapqz8mjm12ekz1kxdx87yceg\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("cookie", "__session=")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://brew.new/api/v1/api-keys")
.header("cookie", "__session=")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"CI\",\n \"permissions\": [\n \"emails\",\n \"domains\"\n ],\n \"brandId\": \"kx7b3s7fapqz8mjm12ekz1kxdx87yceg\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://brew.new/api/v1/api-keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["cookie"] = '__session='
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"CI\",\n \"permissions\": [\n \"emails\",\n \"domains\"\n ],\n \"brandId\": \"kx7b3s7fapqz8mjm12ekz1kxdx87yceg\"\n}"
response = http.request(request)
puts response.read_body{
"key": "brew_abcdefghijklmnopqrstuvwxyz012345",
"keyId": "kd7b3s7fapqz8mjm12ekz1kxdx87yceg",
"message": "Save this key securely. You won't be able to see it again."
}Authorizations
A signed-in Clerk browser session whose active organization role is exactly org:admin. API-key and OAuth actors are rejected.
Body
Was this page helpful?