> ## Documentation Index
> Fetch the complete documentation index at: https://docs.glassmarkets.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an API key

> Creates a scoped API key after password and, when enabled, two-factor verification. The secret value is returned only in this response.



## OpenAPI

````yaml /openapi.yaml post /v1/user/api-keys/
openapi: 3.0.3
info:
  title: Glass Market API
  version: 1.0.0
  x-logo:
    url: https://api.glassmarkets.io/static/black.png
    backgroundColor: '#FFFFFF'
    altText: Glass Market API
  description: >

    Guides, a quickstart and code samples are at

    [docs.glassmarkets.io](https://docs.glassmarkets.io). The API serves the
    data

    behind the GlassMarkets app: market data collected from crypto exchanges,
    and

    market-making data for the assets your organizations work on. The

    [Authentication guide](https://docs.glassmarkets.io/guides/authentication)

    covers login: `POST /v1/login/` returns a token that goes on every request
    as

    `Authorization: Token <token>`.
servers:
  - url: https://api.glassmarkets.io
security: []
tags:
  - name: Authentication
    description: Log in, log out and read the current session.
  - name: Organizations
    description: Your organizations, and the assets, exchanges and pairs each one covers.
  - name: Reported metrics
    description: Volume, depth and spread that market makers report for their assets.
  - name: Trusted metrics
    description: >-
      Volume, depth and spread that Shield measures directly from market makers'
      exchange accounts.
  - name: Market maker metrics
    description: >-
      Market-maker volume, depth, spread, uptime and coverage, combining trusted
      and reported data.
  - name: Targets
    description: >-
      Market-making targets per asset, exchange and pair, and whether they are
      met.
  - name: Market data
    description: >-
      Exchange market data for your assets: volume, spread, order book depth,
      slippage, uptime, futures and more.
  - name: Leaderboard
    description: Trading pairs across exchanges, ranked by market data.
  - name: Loans
    description: Token loans to market makers for your assets.
  - name: RFQ
    description: >-
      Requests for quotes: a project invites market makers to propose
      market-making terms for its token.
  - name: Account
    description: Manage your password, passkeys and two-factor authentication.
externalDocs:
  url: https://docs.glassmarkets.io
  description: Guides, quickstart and code samples
paths:
  /v1/user/api-keys/:
    post:
      tags:
        - Account
      summary: Create an API key
      description: >-
        Creates a scoped API key after password and, when enabled, two-factor
        verification. The secret value is returned only in this response.
      operationId: v1_user_api_keys_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateApiKey'
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/CreateApiKey'
          multipart/form-data:
            schema:
              $ref: '#/components/schemas/CreateApiKey'
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreatedApiKey'
          description: ''
        '400':
          content:
            application/json:
              schema:
                oneOf:
                  - title: Invalid field
                    allOf:
                      - $ref: '#/components/schemas/ValidationErrors'
                  - title: Request
                    allOf:
                      - $ref: '#/components/schemas/ErrorMessage'
              examples:
                WrongPassword:
                  value:
                    password:
                      - Password is incorrect.
                  summary: Wrong password
                CodeRejected:
                  value:
                    message: The authentication code is incorrect.
                  summary: Code rejected
                TooManyKeys:
                  value:
                    message: You can have up to 20 active API keys.
                  summary: Too many keys
          description: >-
            A field is invalid, the password is wrong, the two-factor code is
            missing or rejected, or 20 keys are already active.
        '401':
          $ref: '#/components/responses/Unauthorized'
        '429':
          $ref: '#/components/responses/Throttled'
      security:
        - tokenAuth: []
components:
  schemas:
    CreateApiKey:
      type: object
      properties:
        password:
          type: string
          writeOnly: true
        name:
          type: string
          maxLength: 100
        scopes:
          type: array
          items:
            $ref: '#/components/schemas/ScopesEnum'
        code:
          type: string
          writeOnly: true
          maxLength: 32
      required:
        - name
        - password
        - scopes
    CreatedApiKey:
      type: object
      properties:
        id:
          type: integer
          readOnly: true
        name:
          type: string
          maxLength: 100
        prefix:
          type: string
          maxLength: 16
        scopes: {}
        created_at:
          type: string
          format: date-time
          readOnly: true
        expires_at:
          type: string
          format: date-time
        last_used_at:
          type: string
          format: date-time
          nullable: true
        key:
          type: string
          readOnly: true
      required:
        - created_at
        - expires_at
        - id
        - key
        - name
        - prefix
    ValidationErrors:
      type: object
      description: >-
        One entry per invalid field; `non_field_errors` covers the request as a
        whole. A field carries a list of messages or a single message; a nested
        field carries an object, or a list of objects, of the same shape.
      additionalProperties:
        anyOf:
          - type: array
            items:
              type: string
          - type: string
          - type: object
          - type: array
            items:
              type: object
    ErrorMessage:
      type: object
      properties:
        message:
          type: string
      required:
        - message
    ScopesEnum:
      enum:
        - metrics:read
        - reported_metrics:write
      type: string
      description: |-
        * `metrics:read` - metrics:read
        * `reported_metrics:write` - reported_metrics:write
    ErrorDetail:
      type: object
      properties:
        detail:
          type: string
      required:
        - detail
  responses:
    Unauthorized:
      description: The token is missing, expired or revoked.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorDetail'
          examples:
            InvalidToken:
              value:
                detail: Invalid token.
            MissingToken:
              value:
                detail: Authentication credentials were not provided.
    Throttled:
      description: Too many attempts. Wait the time given in `detail`, then retry.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorDetail'
          examples:
            Throttled:
              value:
                detail: Request was throttled. Expected available in 42 seconds.
  securitySchemes:
    tokenAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Token-based authentication with required prefix "Token ". Example:
        "Token 9944b09199c62bcf9418ad846dd0e4bbdfc6ee4b"
      x-default: Token <token>

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.