CustomDomain™ docs
API referenceTenancy

Ensure the workspace default key exists (secret returned only when created)

POST
/tenants/{tenant_id}/default-key

The workspace default key is an ordinary API key (full workspace access, cd_live_… in production) flagged is_default, at most one active per workspace, whose secret the customer console keeps sealed so the workspace's owner or an admin can view it more than once. Server to server, guarded by the provision secret like tenants:provision; a missing and a wrong secret get the same 401. With no active default key this creates one and answers 201 with the full secret ONCE in api_key. With one, it answers 200 with its id and prefix and no secret (a caller that lost its copy rotates instead). Not subject to the billing activation gate: the key adds no capability the workspace's console key does not already hold.

Authorization

provisionSecret
X-Provision-Secret<token>

Narrow secret for the one-call signup provisioning endpoint (also accepted as a Bearer token).

In: header

Path Parameters

tenant_id*string

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/tenants/string/default-key"
{  "key_id": "string",  "prefix": "string",  "created": true,  "api_key": "string"}
{  "key_id": "string",  "prefix": "string",  "created": true,  "api_key": "string"}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}
{  "code": "string",  "title": "string",  "details": "string"}