← Files GoodMemARCHIVED FILE

skills/goodmem-sdk/references/java/models/CreateApiKeyRequest.md

1.99 KB · Oct 2, 2026 · 00:24 UTC

↓ Download file

<!-- sdk-ref package=ai.pairsys:goodmem-java registry=maven version=0.2.2 -->

# CreateApiKeyRequest

Request parameters for creating a new API key.

Prefer `builder()` to the canonical record constructor.
 Builder-based call sites remain source-compatible when optional fields are added in later SDK versions.

- `labels` (`java.util.Map<String, String>`): Key-value pairs of metadata associated with the API key. Used for organization and filtering. At most 20 entries; keys and values contain at most 255 characters; keys use [a-z0-9._-].
- `expiresAt` (`Long`): Exclusive expiration timestamp in milliseconds since epoch. It must be later than validFrom, which defaults to issuance time; if omitted, the key does not expire.
- `apiKeyId` (`ApiKeyId`): Optional client-provided UUID for idempotent creation. If not provided, server generates a new UUID. Returns ALREADY_EXISTS if ID is already in use. Typed wrapper `ApiKeyId`; build from a raw string with `ApiKeyId.from(String)`.
- `subjectPrincipalId` (`SubjectPrincipalId`): Principal authenticated by this key. Omit to use the authenticated principal. Typed wrapper `SubjectPrincipalId`; build from a raw string with `SubjectPrincipalId.from(String)`.
- `authorityMode` (`ApiKeyAuthorityMode`): Authority mode. Omit to create a self-issued human key that inherits live authority. A scoped issuing credential may create only SCOPED children.
- `ceiling` (`java.util.List<AccessPolicyRule>`): Immutable authorization ceiling. Required and nonempty for SCOPED; omitted for INHERIT_SUBJECT, with at most 1,000 rules. Every rule must be covered by both the subject's live authority and the issuing credential's effective authority.
- `validFrom` (`Long`): Inclusive activation time in epoch milliseconds. Omit to activate at issuance time.

[Java](../../java.md)

Related types — open only those used by your request:

- [AccessPolicyRule](AccessPolicyRule.md)
- [ApiKeyAuthorityMode](ApiKeyAuthorityMode.md)
- [ApiKeyId](ApiKeyId.md)
- [SubjectPrincipalId](SubjectPrincipalId.md)

SHA-256: ea7da9d0d177eb851a57b255328f3496b90daffa6acd33ed6fde32d9f857def6