Skip to content
Streamkap
Esc
↑↓navigate↵open⌘Jpreview

Create Project Key

Create a Project Key with API credentials and optional Kafka access.

Returns a credential file (JSON) with plaintext secrets. This is a one-time delivery - secrets are masked in all subsequent responses. Optionally creates a Kafka user with SCRAM credentials, K8s proxy, and ACLs.

POST/project-keys
Authorization
AuthorizationBearer token · headerrequired
Request body
requiredapplication/json
namestringrequired

Human-readable name for this Project Key

min length 1 · max length 100
descriptionstring | null

Optional description (HTML sanitized)

Show properties
Any of:
string
string
null
null
role_idsstring[] | null

Role IDs to assign. Mutually exclusive with permission_ids.

Show properties
Any of:
string[]
Array of string
string
null
null
permission_idsstring[] | null

Permission IDs to assign directly. Mutually exclusive with role_ids.

Show properties
Any of:
string[]
Array of string
string
null
null
kafka_configProjectKeyKafkaConfig | null

Kafka credentials and ACL config. Omit for API-only key.

Show properties
Any of:
ProjectKeyKafkaConfig
usernamestringrequired

Kafka username (alphanumeric + hyphens, 3-24 chars)

min length 3 · max length 24 · matches ^[a-zA-Z0-9-]+$
passwordstringrequired

Kafka SASL password (12-128 chars)

min length 12 · max length 128
whitelist_ipsstring | null

Comma-separated IP addresses or CIDR ranges

Show properties
Any of:
string
string
null
null
kafka_aclsKafkaAclModel[]

Kafka ACL rules for topic/group access control

Show properties
Array of KafkaAclModel
topic_namestringrequired
operationstringrequired
resource_pattern_typestringrequired
resourcestring
default: "TOPIC"
is_create_schema_registryboolean

Whether to create a Schema Registry proxy

default: false
null
null
tool_profileToolProfile | null

MCP tool profile (full, read-only, agent-operator, infra-admin)

Show properties
Any of:
ToolProfile
string
null
null
allowed_toolsstring[] | null

MCP tool whitelist. If set, overrides profile and block list.

Show properties
Any of:
string[]
Array of string
string
null
null
blocked_toolsstring[] | null

MCP tool blacklist. Removes tools even if profile allows them.

Show properties
Any of:
string[]
Array of string
string
null
null
agentic_enabledboolean

When true, atomically seeds agentic_secret_blob on the new PK row from the credential file produced during creation. The PK is then immediately usable as the auth blob behind the Streamkap MCP. Requires API credentials (role_ids or permission_ids) - rejected with 400 on Kafka-only PKs since there is no API credential to seed. Audit-logged with action=enable. Post-creation toggling goes through POST /project-keys/{id}/enable-agentic or /disable-agentic.

default: false
Responses
201

Successful Response

typestring
default: "streamkap_project_key"
project_key_idstringrequired
projectobjectrequired
apiProjectKeyApiCredentials | null
Show properties
Any of:
ProjectKeyApiCredentials
client_idstringrequired
client_secretstringrequired
token_endpointstringrequired
api_urlstringrequired
rolesstring[]
null
null
kafkaProjectKeyKafkaCredentials | null
Show properties
Any of:
ProjectKeyKafkaCredentials
usernamestringrequired
passwordstringrequired
bootstrap_serversstringrequired
security_protocolstring
default: "SASL_SSL"
sasl_mechanismstring
default: "PLAIN"
schema_registry_urlstring | null
Show properties
Any of:
string
string
null
null
null
null
kafka_aclsobject[]
tool_profileToolProfile | null
Show properties
Any of:
ToolProfile
string
null
null
allowed_toolsstring[] | null
Show properties
Any of:
string[]
Array of string
string
null
null
blocked_toolsstring[] | null
Show properties
Any of:
string[]
Array of string
string
null
null
created_atstring<date-time>required
created_bystring | null
Show properties
Any of:
string
string
null
null
422

Validation Error

detailValidationError[]
Show properties
Array of ValidationError
locstring | integer[]required
Show properties
Array of string | integer
Any of:
string
string
integer
integer
msgstringrequired
typestringrequired
inputany
ctxobject
Request
curl -X POST 'https://api.streamkap.com/project-keys' \
  -H 'Authorization: Bearer YOUR_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "description": "string",
  "role_ids": [
    "string"
  ],
  "permission_ids": [
    "string"
  ],
  "kafka_config": {
    "username": "string",
    "password": "stringstring",
    "whitelist_ips": "string",
    "kafka_acls": [
      {
        "topic_name": "string",
        "operation": "string",
        "resource_pattern_type": "string",
        "resource": "TOPIC"
      }
    ],
    "is_create_schema_registry": false
  },
  "tool_profile": "full",
  "allowed_tools": [
    "string"
  ],
  "blocked_tools": [
    "string"
  ],
  "agentic_enabled": false
}'
Response
{
  "type": "streamkap_project_key",
  "project_key_id": "string",
  "project": {},
  "api": {
    "client_id": "string",
    "client_secret": "string",
    "token_endpoint": "string",
    "api_url": "string",
    "roles": [
      "string"
    ]
  },
  "kafka": {
    "username": "string",
    "password": "string",
    "bootstrap_servers": "string",
    "security_protocol": "SASL_SSL",
    "sasl_mechanism": "PLAIN",
    "schema_registry_url": "string"
  },
  "kafka_acls": [
    {}
  ],
  "tool_profile": "full",
  "allowed_tools": [
    "string"
  ],
  "blocked_tools": [
    "string"
  ],
  "created_at": "2019-08-24T14:15:22Z",
  "created_by": "string"
}