Create Project Key
Create a Project Key with API credentials and optional Kafka access.
Returns a credential file (JSON) with plaintext secrets. This is a one-time delivery - secrets are masked in all subsequent responses. Optionally creates a Kafka user with SCRAM credentials, K8s proxy, and ACLs.
/project-keysAuthorizationBearer token · headerrequiredapplication/jsonnamestringrequiredHuman-readable name for this Project Key
descriptionstring | nullOptional description (HTML sanitized)
Show propertiesHide properties
stringnullrole_idsstring[] | nullRole IDs to assign. Mutually exclusive with permission_ids.
Show propertiesHide properties
stringstringnullpermission_idsstring[] | nullPermission IDs to assign directly. Mutually exclusive with role_ids.
Show propertiesHide properties
stringstringnullkafka_configProjectKeyKafkaConfig | nullKafka credentials and ACL config. Omit for API-only key.
Show propertiesHide properties
usernamestringrequiredKafka username (alphanumeric + hyphens, 3-24 chars)
passwordstringrequiredKafka SASL password (12-128 chars)
whitelist_ipsstring | nullComma-separated IP addresses or CIDR ranges
Show propertiesHide properties
stringnullkafka_aclsKafkaAclModel[]Kafka ACL rules for topic/group access control
Show propertiesHide properties
KafkaAclModeltopic_namestringrequiredoperationstringrequiredresource_pattern_typestringrequiredresourcestringis_create_schema_registrybooleanWhether to create a Schema Registry proxy
nulltool_profileToolProfile | nullMCP tool profile (full, read-only, agent-operator, infra-admin)
Show propertiesHide properties
stringnullallowed_toolsstring[] | nullMCP tool whitelist. If set, overrides profile and block list.
Show propertiesHide properties
stringstringnullblocked_toolsstring[] | nullMCP tool blacklist. Removes tools even if profile allows them.
Show propertiesHide properties
stringstringnullagentic_enabledbooleanWhen true, atomically seeds agentic_secret_blob on the new PK row from the credential file produced during creation. The PK is then immediately usable as the auth blob behind the Streamkap MCP. Requires API credentials (role_ids or permission_ids) - rejected with 400 on Kafka-only PKs since there is no API credential to seed. Audit-logged with action=enable. Post-creation toggling goes through POST /project-keys/{id}/enable-agentic or /disable-agentic.
Successful Response
typestringproject_key_idstringrequiredprojectobjectrequiredapiProjectKeyApiCredentials | nullShow propertiesHide properties
client_idstringrequiredclient_secretstringrequiredtoken_endpointstringrequiredapi_urlstringrequiredrolesstring[]nullkafkaProjectKeyKafkaCredentials | nullShow propertiesHide properties
usernamestringrequiredpasswordstringrequiredbootstrap_serversstringrequiredsecurity_protocolstringsasl_mechanismstringschema_registry_urlstring | nullShow propertiesHide properties
stringnullnullkafka_aclsobject[]tool_profileToolProfile | nullShow propertiesHide properties
stringnullallowed_toolsstring[] | nullShow propertiesHide properties
stringstringnullblocked_toolsstring[] | nullShow propertiesHide properties
stringstringnullcreated_atstring<date-time>requiredcreated_bystring | nullShow propertiesHide properties
stringnullValidation Error
detailValidationError[]Show propertiesHide properties
ValidationErrorlocstring | integer[]requiredShow propertiesHide properties
string | integerstringintegermsgstringrequiredtypestringrequiredinputanyctxobject