BizKitHub
DocsAPI ReferenceCustomer/api/v1/customer/create-api-key
postCustomerPublic API v1

/api/v1/customer/create-api-key

Generates a new API key (identity) for an authenticated customer. The key can be scoped to a specific workspace.

customerpostApiV1CustomerCreate-api-key

Parameters

1 query · JSON body

Query parameters

· 1
apiKeystringRequired

Your BizKitHub API key (passed as GET parameter).

Key format: A 32-character string matching: ^(PROD|DEV_|ROOT)[A-Za-z0-9]{28}$
Prefixes: PROD (production key), DEV_ (individual developer), ROOT (system key with no limits). Learn more

ExamplePRODPGrFxpGEtrOZfuWhnoJohUYBXuOE

Request body

application/json
identityIdstringRequired

Logged user identity (from your frontend cookies). Learn more

ExampleZ9CPkS2o3UV163VQn5OUv0T8BQi8Fvdg
descriptionstringOptional
ExampleUser Jan Barasek
workspaceCodestringOptional
Examplemy-workspace
customerRealIpstringOptional

Accepted formats:

  • IPv4 dot-decimal, e.g. 1.1.1.1 (4 octets, 0–255, no leading zeros).
  • IPv6 as defined by RFC 4291 — full 2001:0db8:0000:0000:0000:0000:0000:0001, zero-compressed 2001:db8::1, IPv4-mapped ::ffff:1.2.3.4, or scoped literals. Both upper- and lower-case hex are accepted.

Server-side canonicalization (ipNormalize in core/src/lib/network/ipNormalize.ts):

  • Valid IPv4 is passed through verbatim.
  • Valid IPv6 is lowercased (RFC 5952 §4.3).
  • IPv4-mapped IPv6 ::ffff:X.X.X.X is unwrapped to plain IPv4 (RFC 4291 §2.5.5.2) so 1.2.3.4 and ::ffff:1.2.3.4 share one brj__geo_ip row.
  • Loopback aliases (::1, 0.0.0.0, localhost, empty string) collapse to 127.0.0.1.
  • Junk values that fail both IPv4 and IPv6 validation are silently rejected and replaced with 127.0.0.1 (loopback).

On the wire: every response returns the canonicalized form — clients can safely rely on lowercase IPv6 and the plain-IPv4 unwrap when de-duping or joining. Server-originated writers (activity log, session log, ban list) resolve the visitor IP via resolveClientIp / resolveClientIpOrNull — always native IPv6 on Vercel Edge (there is no auto-mapping to ::ffff:X.X.X.X).

Enrichment: the system resolves reverse DNS, geolocation, ASN, mobile/proxy/hosting/Tor flags via our VikiTron GEO/IP resolver for both address families. Learn more

Examples1.1.1.12001:4860:4860::8888

Response schema

1 status code documented

200Success
success"true"Required
apiKeystringRequired
Example63VQn5OUY2zfcPdz1I8s2rWzI2KyOX0z
expirationDateDate | string | string | numberRequired
One of 4:
Variant 1
Date
Example2025-01-10T16:19:40.150Z
Variant 2
stringdate-time
Variant 3
stringdate
Variant 4
number

Response example

application/json
{
  "success": true,
  "apiKey": "63VQn5OUY2zfcPdz1I8s2rWzI2KyOX0z",
  "expirationDate": "2025-01-10T16:19:40.150Z"
}

Request example

POST /api/v1/customer/create-api-key

post
curl -X POST "https://api.bizkithub.com/api/v1/customer/create-api-key?apiKey=PRODPGrFxpGEtrOZfuWhnoJohUYBXuOE" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{
  "identityId": "Z9CPkS2o3UV163VQn5OUv0T8BQi8Fvdg",
  "description": "User Jan Barasek",
  "workspaceCode": "my-workspace",
  "customerRealIp": "1.1.1.1"
}'

Need an API key?

All BizKitHub public API endpoints require authentication via API key.

Get API Key