1. Docs
  2. API Reference
  3. Create a publishable key

Create a publishable key

POST/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/publishable-keys

Mints a new publishable key of the given type. A web key delivers refresh tokens as an httpOnly cookie the browser guards; a native key returns them in the response body for a phone app to store in the OS keychain. The type is fixed at creation โ€” a key cannot be converted later, because sessions already issued from it carry the delivery it implied.

Authentication

Bearer TokenAuthorization

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

Requires capability publishable_keys.manageDeveloper Console

Create, rename, and revoke publishable keys. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.

Request body

application/json

typeenum Required

What kind of app will hold this key, which decides how a session created with it receives its refresh token. `web` delivers an httpOnly cookie the browser guards; `native` returns the token in the response body for a phone app to store in the OS keychain. Fixed at creation โ€” a key cannot be converted later, because sessions already issued from it carry the delivery it implied.

one of "web" ยท "native"

namestring Required

Label shown in the dashboard, so several keys on one environment are tellable apart (e.g. "iOS app", "marketing site").

max length 100

Responses

application/json

  • dataPublishableKeyResponseDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Errors

When the request can't be completed, the response body includes a stable error code you can branch on.

403account.capability_requiredForbidden
When it happens

The signed-in user's administrator roles do not grant the capability this endpoint requires.

Remediation

Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.

Returned object

Request
curl -X POST "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/applications/{appSlug}/environments/{envSlug}/publishable-keys" \
  -H "Authorization: Bearer $CANOPY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "web",
    "name": "string"
  }'
Response
{
  "data": {
    "id": "string",
    "key": "string",
    "type": "web",
    "name": "string",
    "created_at": "2026-04-20T12:00:00.000Z"
  }
}
Related endpoints
GETList the environment's publishable keys
PATCHRename a publishable key
DELETERevoke a publishable key
Was this page helpful?

Tell us how we can improve this guide.