---
title: "Create a personal API key for this app"
description: "Mints a key that acts as you, in this app, with at most the permissions you already have, a key can never do more than the user who made it."
canonical: "https://gtable.app/docs/app-api/me/keys-create"
updated: "2026-10-05"
---

# Create a personal API key for this app

`POST https://your-suite.gtable.app/your-app/v1/me/keys`

Mints a key that acts as you, in this app, with at most the permissions you already have, a key can never do more than the user who made it.

> **Note: Generic contract**
>
> Your own version of this operation, with your tables and the fields you can read, is in
> your app's document: `https://{suite}.gtable.app/{app}/v1/openapi.json`, behind your credential.
> [Why each person gets their own](/docs/start/studio-and-runtime#why-an-app-has-an-api-of-its-own).

Only from a signed-in browser: a key or a connected agent cannot mint another. Expires in 90 days unless you choose otherwise; `expiresInDays: null` lives until revoked. The key is returned once and never stored in clear.

Any valid credential for this API: no scope is needed. Operation `me.keys.create`. Not an MCP tool: keys are made by a person in a signed-in browser. CLI, once published: `gtable me keys create`.

## Headers

| Name              | Type   | Required | Description                                                                                                                                                                                                                                                        |
| ----------------- | ------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `Idempotency-Key` | string | no       | Any unique string. Sending the same key with the same request again returns the first response (marked `Idempotency-Replayed: true`) instead of running it twice. Reusing it for a different request is refused with 409. Kept for 24 hours. Up to 255 characters. |

## Request body

| Field           | Type            | Required | Description           |
| --------------- | --------------- | -------- | --------------------- |
| `name`          | string          | yes      | Up to 120 characters. |
| `scopes`        | string\[]       | yes      |                       |
| `expiresInDays` | integer or null | no       |                       |
