01Run it
Replace the <placeholders> with your own values, or use the builder below.
p202 user apikey create <user_id>02What you get
Pick the shape you need. People get a table. Add
--json, --csv or --ndjson for scripts, or -q for ids only. An AI agent gets compact JSON without asking. All output formats03Build your command
Pick values and the command line writes itself, quoted and ready to paste.
p202 user apikey createSet flags below; the command updates as you type.
04Flags
1 flag, plus the global flags every command takes.
| Flag | What it does |
|---|---|
| --scopestring | Scope for the new key: *, read, write, stage, or comma-separated <area>:read/<area>:write/<area>:stage tokens (read,stage is the propose-only agent shape; default: full access) |
05How it works
Create an API key. --scope attenuates the key: read for a key that can
never write (reporting agents), write for full read/write, or granular
stage for a propose-only key, or granular <area>:read/<area>:write/
<area>:stage tokens (comma-separated), e.g.
reports:read,forecast-events:read. Without --scope the key has full
access (*). A scoped key cannot mint a key broader than itself.
06For agents
Running this from an agent
- Read the same facts as JSON:
p202 commands user apikey create --json. - With
AI_AGENT,CLAUDECODEor another agent variable set, output is compact JSON and errors arrive on stderr as a JSON envelope with ahint. - Exit codes: 0 ok, 1 bad input, 2 auth, 3 network, 4 server error, 5 partial failure.
- This command writes. Add
--stagedto record it as a proposal a person applies withp202 change apply.
{
"path": "p202 user apikey create",
"use": "create <user_id>",
"short": "Create an API key for a user",
"long": "Create an API key. --scope attenuates the key: `read` for a key that can\nnever write (reporting agents), `write` for full read/write, or granular\n`stage` for a propose-only key, or granular `<area>:read`/`<area>:write`/\n`<area>:stage` tokens (comma-separated), e.g.\n`reports:read,forecast-events:read`. Without --scope the key has full\naccess (`*`). A scoped key cannot mint a key broader than itself.",
"runnable": true,
"flags": [
{
"name": "scope",
"type": "string",
"default": "",
"usage": "Scope for the new key: *, read, write, stage, or comma-separated <area>:read/<area>:write/<area>:stage tokens (`read,stage` is the propose-only agent shape; default: full access)",
"required": false
}
]
}