curl --request POST \
--url https://app.thinnest.ai/api/v1/customers/{id}/keys \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Sunrise front-desk dashboard",
"scope": "read"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({name: 'Sunrise front-desk dashboard', scope: 'read'})
};
fetch('https://app.thinnest.ai/api/v1/customers/{id}/keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/customers/{id}/keys"
payload = {
"name": "Sunrise front-desk dashboard",
"scope": "read"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "0c7e4a92-3d1b-4f6a-8e25-91b7c3d4f5a6",
"name": "Sunrise front-desk dashboard",
"prefix": "ta_live_Xk3pQ9",
"scope": "read",
"createdAt": "2026-10-06T10:12:45.330Z",
"lastUsedAt": null,
"revokedAt": null,
"key": "ta_live_Xk3pQ9vLr2mT7yHc4bN8sJd1Wq6Ez0aUo5iKf3gPxRt"
}{
"error": "`name` is 2-80 characters, so you know what to revoke later."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "This API key is read-only: it can read everything but change nothing."
}{
"error": "Customer not found."
}{
"error": "This workspace resells the console under white label: its workspaces are clients, managed in White label → Clients, not API customers."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Create Customer Key
Mints an API key that works in this one customer only — to give your customer its own API access, or to run one customer’s integration on a key that cannot reach the others. The full key (ta_live_…) is in this response once; store it, because it is never shown again. Its usage is still charged to you. Needs a full key.
curl --request POST \
--url https://app.thinnest.ai/api/v1/customers/{id}/keys \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "Sunrise front-desk dashboard",
"scope": "read"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({name: 'Sunrise front-desk dashboard', scope: 'read'})
};
fetch('https://app.thinnest.ai/api/v1/customers/{id}/keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/customers/{id}/keys"
payload = {
"name": "Sunrise front-desk dashboard",
"scope": "read"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "0c7e4a92-3d1b-4f6a-8e25-91b7c3d4f5a6",
"name": "Sunrise front-desk dashboard",
"prefix": "ta_live_Xk3pQ9",
"scope": "read",
"createdAt": "2026-10-06T10:12:45.330Z",
"lastUsedAt": null,
"revokedAt": null,
"key": "ta_live_Xk3pQ9vLr2mT7yHc4bN8sJd1Wq6Ez0aUo5iKf3gPxRt"
}{
"error": "`name` is 2-80 characters, so you know what to revoke later."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "This API key is read-only: it can read everything but change nothing."
}{
"error": "Customer not found."
}{
"error": "This workspace resells the console under white label: its workspaces are clients, managed in White label → Clients, not API customers."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Path Parameters
The customer's id (org_…), as Create Customer answered.
Body
What the key is for, so you know what to revoke later. Trimmed.
2 - 80"Sunrise front-desk dashboard"
The key's access level: full, build (everything except messaging customers, sending codes and placing calls) or read.
full, build, read "read"
Response
The key, with its secret shown this once.
A new key, with its secret.
The key's id, for revoking it.
"0c7e4a92-3d1b-4f6a-8e25-91b7c3d4f5a6"
What you called it.
"Sunrise front-desk dashboard"
The key's first characters, so you can tell keys apart.
"ta_live_Xk3pQ9"
Its access level: full everything; build everything except messaging customers, sending codes and placing calls; read reads only.
full, build, read "read"
"2026-10-03T08:22:10.511Z"
When it last made a request; null if never.
"2026-10-06T09:58:47.090Z"
When it was revoked; null while it works.
null
The key itself, to send as Authorization: Bearer <key>. Shown in this response only.
"ta_live_Xk3pQ9vLr2mT7yHc4bN8sJd1Wq6Ez0aUo5iKf3gPxRt"