> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ohmyho.st/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For account actions, read https://ohmyho.st/skills/ohmyhost-get-started/SKILL.md and use the authenticated ohmyho.st CLI or local product MCP. Mintlify search only reads documentation. Preserve the customer’s selected project, environment and authentication provider.

# Create a user-owned API token valid until revoked

> Requires a current interactive user session. Organization membership and product permissions are revalidated. Only the first creation returns the full value; exact replay returns metadata and a null value. Save the first response locally without putting it in logs or agent prompts. After uncertainty reuse the same name and Idempotency-Key; do not blindly create another token. Available at zero credits.



## OpenAPI

````yaml /openapi.json post /v1/organizations/{organization_id}/user-api-keys
openapi: 3.1.2
info:
  title: ohmyho.st API
  version: 0.0.0
  description: >-
    Public REST API for ohmyho.st hosting, projects, domains, email, credits and
    exports.
servers:
  - url: https://app.ohmyho.st
    description: Production control API
  - url: https://dev.app.ohmyho.st
    description: Development control API
security:
  - BearerAuth: []
paths:
  /v1/organizations/{organization_id}/user-api-keys:
    post:
      summary: Create a user-owned API token valid until revoked
      description: >-
        Requires a current interactive user session. Organization membership and
        product permissions are revalidated. Only the first creation returns the
        full value; exact replay returns metadata and a null value. Save the
        first response locally without putting it in logs or agent prompts.
        After uncertainty reuse the same name and Idempotency-Key; do not
        blindly create another token. Available at zero credits.
      operationId: createUserApiKey
      parameters:
        - $ref: '#/components/parameters/RequestId'
        - $ref: '#/components/parameters/IdempotencyKey'
        - name: organization_id
          in: path
          required: true
          schema:
            $ref: '#/components/schemas/Ulid'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              required:
                - name
              properties:
                name:
                  type: string
                  minLength: 1
                  maxLength: 64
      responses:
        '200':
          description: Original token observed; the full value cannot be retrieved again.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserApiKeyCreation'
        '201':
          description: Token created; the full value is returned once.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/UserApiKeyCreation'
        '400':
          $ref: '#/components/responses/Problem'
        '401':
          $ref: '#/components/responses/Problem'
        '403':
          $ref: '#/components/responses/Problem'
        '404':
          $ref: '#/components/responses/ResourceNotFound'
        '409':
          $ref: '#/components/responses/Problem'
        '429':
          $ref: '#/components/responses/Problem'
        '503':
          $ref: '#/components/responses/Problem'
components:
  parameters:
    RequestId:
      name: X-Request-Id
      in: header
      description: Optional caller-provided correlation identifier.
      required: false
      schema:
        type: string
        minLength: 1
        maxLength: 128
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      description: Identifies one mutation and its canonical request payload.
      required: true
      schema:
        type: string
        minLength: 1
        maxLength: 128
  schemas:
    Ulid:
      type: string
      pattern: ^[0-9A-HJKMNP-TV-Z]{26}$
    UserApiKeyCreation:
      type: object
      additionalProperties: false
      required:
        - request_id
        - replayed
        - key
        - value
      properties:
        request_id:
          $ref: '#/components/schemas/Ulid'
        replayed:
          type: boolean
        key:
          $ref: '#/components/schemas/UserApiKey'
        value:
          type:
            - string
            - 'null'
          pattern: ^sk_[A-Za-z0-9_-]{20,128}$
      oneOf:
        - properties:
            replayed:
              const: false
            value:
              type: string
        - properties:
            replayed:
              const: true
            value:
              type: 'null'
    UserApiKey:
      type: object
      additionalProperties: false
      required:
        - id
        - organization_id
        - name
        - obfuscated_value
        - permissions
        - expires_at
        - created_at
        - last_used_at
      properties:
        id:
          $ref: '#/components/schemas/UserApiKeyId'
        organization_id:
          $ref: '#/components/schemas/Ulid'
        name:
          type: string
          minLength: 1
          maxLength: 128
        obfuscated_value:
          type: string
          pattern: ^sk_(?:\.\.\.|…)[A-Za-z0-9_-]{1,12}$
        permissions:
          type: array
          maxItems: 100
          uniqueItems: true
          items:
            type: string
            pattern: ^[A-Za-z0-9_.*:-]{1,128}$
        expires_at:
          type:
            - string
            - 'null'
          format: date-time
        created_at:
          type: string
          format: date-time
        last_used_at:
          type:
            - string
            - 'null'
          format: date-time
    ProblemDetails:
      type: object
      description: RFC 9457 Problem Details extended with stable ohmyhost recovery fields.
      additionalProperties: false
      required:
        - type
        - title
        - status
        - code
        - request_id
        - retryable
        - suggested_action
      properties:
        type:
          type: string
          format: uri-reference
        title:
          type: string
          minLength: 1
        status:
          type: integer
          minimum: 400
          maximum: 599
        detail:
          type: string
        instance:
          type: string
          format: uri-reference
        code:
          type: string
          enum:
            - invalid_request
            - unauthenticated
            - forbidden
            - resource_not_found
            - idempotency_key_reused
            - project_handle_unavailable
            - project_identity_unavailable
            - deployment_plan_expired
            - deployment_plan_incompatible
            - confirmation_expired
            - confirmation_invalid
            - etag_mismatch
            - promotion_source_stale
            - promotion_target_stale
            - promotion_invalid_target
            - mail_domain_conflict
            - mail_domain_required
            - framework_conversion_required
            - migration_filename_noncanonical
            - environment_secret_mutation_blocked
            - container_runtime_required
            - payload_too_large
            - rate_limited
            - insufficient_organization_credits
            - paid_plan_required
            - project_budget_exceeded
            - compute_performance_paid_required
            - compute_performance_unavailable
            - compute_change_pending
            - compute_change_conflict
            - billing_purchase_conflict
            - billing_recharge_conflict
            - cloudflare_authorization_closed
            - project_notes_conflict
            - project_export_not_ready
            - interactive_login_required
            - api_key_creation_uncertain
            - api_key_permissions_unavailable
            - reconciliation_exhausted
            - service_unavailable
        request_id:
          type: string
          minLength: 1
          maxLength: 128
        retryable:
          type: boolean
        retry_after_seconds:
          type: integer
          minimum: 1
          maximum: 86400
          description: >-
            Optional machine-readable retry delay for a rate limit, matching
            Retry-After.
        suggested_action:
          type: string
          minLength: 1
    UserApiKeyId:
      type: string
      pattern: ^api_key_[A-Za-z0-9_]{1,120}$
  responses:
    Problem:
      description: The request failed.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
    ResourceNotFound:
      description: >-
        The resource does not exist or is not visible to the authenticated
        principal.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/XRequestId'
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ProblemDetails'
          examples:
            resourceNotFound:
              value:
                type: https://docs.ohmyho.st/errors/resource-not-found
                title: Resource not found
                status: 404
                code: resource_not_found
                request_id: req_01J00000000000000000000000
                retryable: false
                suggested_action: Check the resource identifier and your access scope.
  headers:
    XRequestId:
      description: Correlates the request with operations, events, logs, and audit records.
      required: true
      schema:
        type: string
        minLength: 1
        maxLength: 128
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        WorkOS access JWT or a user-owned WorkOS API key. User keys are bound to
        one organization and restricted to their enabled product permissions.
        Session-only onboarding and session revocation require an interactive
        access JWT. No cookie session is assumed.

````