Skip to main content
POST
Error

Authorizations

Authorization
string
header
required

Management API authentication for /api/* endpoints. Use the Authorization header with Bearer <token>, where <token> is one of:

  • a Bifrost management API key,
  • a dashboard session token issued by POST /api/session/login,
  • base64 of <admin-username>:<admin-password> (legacy equivalent of BasicAuth).

Virtual keys (sk-bf-*) and the x-api-key header are not accepted on management APIs - the sole exception is GET /api/governance/virtual-keys/quota, which is virtual-key-only.

Authentication alone is not sufficient in Bifrost Enterprise: each operation page shows a Required Permissions table (Resource:Operation, for example Dashboard:View) above its Authorizations section, and the caller's RBAC role or management API key scopes must include what it lists, otherwise the request is rejected with 403 Forbidden.

A local admin — authenticated with the admin password, or any caller on a deployment with dashboard auth disabled — bypasses these checks and can call every management endpoint.

OSS setup lock. On Bifrost OSS, while dashboard auth is not active (no admin account, or auth disabled), every management endpoint except the public ones (/health, /api/version, /api/session/is-auth-enabled, /api/session/login, ...) requires the operator's setup token in the X-Bifrost-Setup-Token header, in place of Authorization. The token is set with setup_token in config.json or the BIFROST_SETUP_TOKEN environment variable. A missing header returns 401, a wrong token 403. The header stops working once dashboard auth is enabled. The dashboard instead trades the token once for an HttpOnly bifrost_setup_session cookie via POST /api/session/setup. See Required permissions for how permissions are derived and which endpoints are exempt.

Body

application/json

Create body for a management API key. The key value is generated by the server and can never be supplied here.

name
string
required

Unique name for the key.

description
string | null

Optional note about what the key is for.

scopes
integer<uint>[]

Permission ids to grant, from GET /api/governance/rbac/permissions. A key carries only the permissions listed here — the creator's own role is not inherited. You cannot grant a permission you do not hold yourself; doing so returns 403.

expires_at
string<date-time> | null

Expiry timestamp in RFC3339 format. Omit or send null for a key that never expires.

Response

Key created. The full key value is returned once.

Creation response. This is the only time the full key value is returned — store it immediately, as it cannot be retrieved again.

api_key
object

A management API key. The key value itself is never returned after creation — only the truncated key_prefix is, so keys can be told apart in a list.

key
string

The full key value, shown only once. Send it in the Authorization header as Bearer <key>.

Example:

"bfst-A1b2C3d4E5f6G7h8I9j0K1l2M3n4O5p6Q7r8S9t0U1v2"