> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hyperprop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an API key

> Create your organization's API key. **Admin only.** You normally do this in the dashboard.

The response contains the **full key exactly once** — copy it immediately; it can't be retrieved later. The key carries `read`, `write`, and `admin` permissions and does not expire.

**One key per organization for now:** if a key already exists, creation fails with `409 KEY_LIMIT_REACHED`. To rotate, delete the old key (see `DELETE /api-keys/{keyId}`) and create a new one — the old key stops working the moment you delete it, so update your backend configuration in the same maintenance window.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/organization/api-keys
openapi: 3.0.0
info:
  title: Hyperprop Platform API
  version: 1.0.0
  description: >-
    REST API for the Hyperprop Trading Platform — provision evaluation and
    funded trading accounts, manage traders and plans, react to account
    lifecycle events via signed webhooks, and reconcile billing. Built for prop
    firms integrating from their own backend.


    Authentication, quick start, error handling, idempotency, pagination, custom
    metadata, webhooks, and the MCP connector are documented at
    https://docs.hyperprop.com.
  x-logo:
    url: https://app.hyperprop.com/logo-icon.svg
    altText: Hyperprop
    href: https://hyperprop.com
servers:
  - url: https://api.hyperprop.com/platform
    description: Production
security: []
tags:
  - name: Trading accounts
    description: Create, update, and inspect trading accounts.
  - name: Traders
    description: Look up and update the traders in your organization.
  - name: Trading plans
    description: Define the plans you sell.
  - name: Trading rules
    description: Define how accounts are evaluated.
  - name: Lockouts
    description: Pause and resume trading on an account.
  - name: Payouts
    description: Check payout eligibility and record payouts.
  - name: Purchases
    description: Purchases recorded for your organization.
  - name: Time Machine
    description: Restore accounts to an earlier trading day or instant.
  - name: Webhooks
    description: Register webhook endpoints and inspect deliveries.
  - name: Events
    description: Your organization's event history and real-time event stream.
  - name: Reconciliation
    description: Balances, end-of-day snapshots, and fills for reconciliation.
  - name: Analytics
    description: Organization performance and plan economics.
  - name: Billing
    description: 'Your Hyperprop bill: activity, billing cycles, and forecasts.'
  - name: Team and roles
    description: Manage dashboard access for your staff.
  - name: API keys
    description: Manage your organization's API key.
  - name: Logs and health
    description: API request logs, the audit log, and integration health.
  - name: Organization profile
    description: Your organization's profile and logo.
  - name: Support
    description: Open and follow up on support tickets.
  - name: Partner access
    description: >-
      Read a trader's journal as an approved partner app, with the trader's own
      key.
paths:
  /v1/organization/api-keys:
    post:
      tags:
        - API keys
      summary: Create an API key
      description: >-
        Create your organization's API key. **Admin only.** You normally do this
        in the dashboard.


        The response contains the **full key exactly once** — copy it
        immediately; it can't be retrieved later. The key carries `read`,
        `write`, and `admin` permissions and does not expire.


        **One key per organization for now:** if a key already exists, creation
        fails with `409 KEY_LIMIT_REACHED`. To rotate, delete the old key (see
        `DELETE /api-keys/{keyId}`) and create a new one — the old key stops
        working the moment you delete it, so update your backend configuration
        in the same maintenance window.
      operationId: postV1OrganizationApikeys
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Model533'
      responses:
        '201':
          description: API key created — the raw key is shown only in this response
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model536'
        '401':
          description: Authentication required
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model9'
        '403':
          description: Access denied
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model47'
        '409':
          description: Key limit reached (one key per organization for now)
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model537'
        '500':
          description: An unexpected error occurred
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/Model5'
      security:
        - X-API-Key: []
components:
  schemas:
    Model533:
      type: object
      properties:
        name:
          type: string
          description: Label for the key so you remember where it is used
          example: Production backend
          default: Default Key
          minLength: 1
          maxLength: 100
    Model536:
      type: object
      properties:
        success:
          type: boolean
          example: true
        message:
          type: string
          example: API key created. Copy it now — it will not be shown again.
        data:
          $ref: '#/components/schemas/Model535'
    Model9:
      type: object
      properties:
        success:
          type: boolean
          description: Always false on errors
          example: false
        statusCode:
          type: number
          example: 401
        error:
          type: string
          example: Unauthorized
        message:
          type: string
          example: Authentication required
        code:
          type: string
          description: Machine-readable error code — switch on this, not on message text
          example: UNAUTHORIZED
    Model47:
      type: object
      properties:
        success:
          type: boolean
          description: Always false on errors
          example: false
        statusCode:
          type: number
          example: 403
        error:
          type: string
          example: Forbidden
        message:
          type: string
          example: Access denied
        code:
          type: string
          description: Machine-readable error code — switch on this, not on message text
          example: FORBIDDEN
    Model537:
      type: object
      properties:
        success:
          type: boolean
          example: false
        code:
          type: string
          example: KEY_LIMIT_REACHED
        message:
          type: string
          example: >-
            Your organization already has an API key. Delete the existing key
            first — only one key is allowed for now.
    Model5:
      type: object
      properties:
        success:
          type: boolean
          description: Always false on errors
          example: false
        statusCode:
          type: number
          example: 500
        error:
          type: string
          example: Internal Server Error
        message:
          type: string
          example: An unexpected error occurred
        code:
          type: string
          description: Machine-readable error code — switch on this, not on message text
          example: INTERNAL_ERROR
    Model535:
      type: object
      example:
        id: b7d2f1a0-1c2d-4e5f-8a9b-0c1d2e3f4a5b
        name: Production backend
        keyPrefix: hp_live_a1b2c3d4
        permissions:
          - read
          - write
          - admin
        isActive: true
        createdAt: '2026-07-21T20:30:00.000Z'
        key: hp_live_your_key_here
      properties:
        id:
          type: string
        name:
          type: string
        keyPrefix:
          type: string
        permissions:
          $ref: '#/components/schemas/Model534'
        isActive:
          type: boolean
        createdAt:
          type: string
        key:
          type: string
          description: The full API key — shown exactly once
    Model534:
      type: array
      items:
        type: string
  securitySchemes:
    X-API-Key:
      type: apiKey
      name: X-API-Key
      in: header
      description: >-
        Organization API key. Format: "hp_live_{key}". Organization admins
        manage the key in the dashboard.

````

## Related topics

- [Bulk-create unlinked accounts with import keys](/platform-api/trading-accounts/bulk-create-unlinked-accounts-with-import-keys.md)
- [Generate a trader API key for third-party access](/trade-api/account/generate-a-trader-api-key-for-third-party-access.md)
- [Delete an API key](/platform-api/api-keys/delete-an-api-key.md)
- [List the trader's API keys](/trade-api/account/list-the-traders-api-keys.md)
- [Authentication](/authentication.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.