Create an API key

Create a sub-account API key (cfy_ followed by 32 random bytes, base64url). The full key is returned in this response only — it is not stored (only a SHA-256 hash, prefix and last four are) and can't be retrieved again.

POST https://api.centerfy.ai/webhooks/inbound/agency/sub-accounts/:id/api-keys

Headers

HeaderRequiredValueDescription
x-api-keyYesyour agency API key (cfy_…)Agency (organization-wide) API key, created in the agency workspace under Settings → API Keys (“Agency API Keys”; the tab only appears on White Label or SaaS Mode plans). Or send Authorization: Bearer <key>; x-api-key wins if both are present. Keys must start with cfy_. A sub-account key is rejected with 401.
Content-TypeYesapplication/jsonThe request body is JSON.

Path parameters

NameTypeRequiredDescription
idstring (uuid)YesThe sub-account id. Must belong to the key’s agency and not be deleted.

Body parameters

NameTypeRequiredDefaultDescription
namestringYes—Label for the key, 1–100 characters.

Request body

{
  "name": "Zapier"
}

Example

curl -X POST "https://api.centerfy.ai/webhooks/inbound/agency/sub-accounts/{id}/api-keys" \
  -H "x-api-key: $CENTERFY_AGENCY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "Zapier"
}'
import { CenterfyAgencyClient } from "@centerfy/sdk";

const agency = new CenterfyAgencyClient({ apiKey: process.env.CENTERFY_AGENCY_API_KEY! });

const result = await agency.subAccountApiKeys.create("<subAccountId>", {
  "name": "Zapier"
});
console.log(result);
centerfy --agency subAccountApiKeys create <subAccountId> '{"name":"Zapier"}'

MCP tool: centerfy_agency_sub_account_api_keys_create (see MCP server)

Response

{
  "status": "success",
  "api_key": {
    "id": "b07f9284-e1a3-44c5-b061-7c8d9eafb007",
    "name": "Zapier",
    "key_prefix": "cfy_Q3vX",
    "last_four": "k9Tz",
    "created_at": "2026-10-02T11:00:00.000Z",
    "last_used_at": null
  },
  "key": "cfy_Q3vXexampleexampleexampleexampleexamplek9Tz",
  "warning": "Store this key now — it cannot be retrieved again."
}

Errors

  • 201 — on success.
  • 400 — if name is blank.
  • 404 — when the sub-account id is not a uuid, does not exist, is deleted, or belongs to another agency.
  • 401 — when the key is missing, not cfy_-prefixed or unknown (including sub-account keys); 403 when the agency is not on a White Label or SaaS Mode plan; 429 above 50 requests per minute per agency (Retry-After header set); 500 ‘database error’ on an internal failure.

Notes

Currently returns 503 ‘API key creation through the agency API is not available yet (api_keys.plaintext_key must become nullable)’: the endpoint never writes the plaintext, and the database still requires api_keys.plaintext_key (NOT NULL), so the insert is refused rather than storing the key. It starts working once that column is made nullable.

© 2026 Centerfy AI. All rights reserved.