Create an API key
Creates an API key for the caller’s organization. The response’s token field is the only time the plaintext credential is returned — store it immediately; only its hash is persisted. Optionally pin the key to a single property. Keys carry the full read scope set (never write:integrations or key management). Session auth only.
Authorizations
Authorization: Bearer <token>. Token types resolve to the same scoped credential: a user-generated API key (casa_…, from Account settings — recommended for machines and MCP clients), a WorkOS AuthKit session JWT (the web app; org and role come from verified token claims), or a static token. API keys are group-scoped, optionally pinned to one property at creation. MCP OAuth connector tokens authenticate the MCP server only and are rejected on these REST routes.
Headers
Active WorkOS organization (property group). Optional cross-check for session (JWT) auth: when sent it must equal the token's verified org_id claim, else 403. The org is taken from the claim, not this header. Ignored for API keys and static tokens.