Create a new Environment in an Application
/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environmentsCreates a new Environment in the active Application from a name and optional slug (derived from the name when omitted), returning 201 with the Environment plus one-time oauth_client_rotations and webhook_subscription_rotations receipts. When copy_from names an existing Environment slug, that source's permissions, roles, role-permission joins, hierarchy nodes, OAuth client configs, and webhook configs are cloned — with freshly minted publishable key, OAuth client ids/secrets, and webhook signing secrets, since secrets never cross between Environments; identities, memberships, assignments, audit logs, and deliveries are not copied. A duplicate slug within the Application returns 409 and an environment.created audit event is emitted.
Authentication
AuthorizationJWT access token. Never send alongside X-API-Key: a request carrying both is refused.
applications.manageDeveloper ConsoleCreate, edit, and delete Applications and Environments. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.
Request body
application/json
namestring Required Display name for the new Environment
slugstring Optional URL-safe slug. Lowercase alphanumeric with optional dashes (no leading/trailing dash). Auto-derived from `name` when omitted. Unique within the Application.
copy_fromstring Optional Source env slug to clone configuration from. Copies permissions, roles, role-permission joins, hierarchy nodes, OAuth client configs (without secrets), and webhook configs (without secrets). Identities and role assignments are NOT copied.
Responses
application/json
data *EnvironmentCloneResponseDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
Errors
When the request can't be completed, the response body includes a stable error code you can branch on.
account.capability_requiredForbiddenThe signed-in user's administrator roles do not grant the capability this endpoint requires.
Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.
Returned object
curl -X POST "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments" \ -H "Authorization: Bearer $CANOPY_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "name": "string", "slug": "string", "copy_from": "string" }'
{ "data": { "environment": { "id": "string", "application_id": "string", "name": "string", "slug": "string", "is_production": false, "settings": {}, "version": 0, "created_at": "2026-04-20T12:00:00.000Z", "updated_at": "2026-04-20T12:00:00.000Z" }, "oauth_client_rotations": [ { "source_client_id": "string", "client_id": "string", "client_secret": "string" } ], "webhook_subscription_rotations": [ { "id": "string", "url": "string", "secret": "string" } ] } }
Tell us how we can improve this guide.