> ## Documentation Index
> Fetch the complete documentation index at: https://apidoc.cometapi.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Tạo API key

> Sử dụng CometAPI POST /api/token/ để tạo API key cho tài khoản đã xác thực.

Sử dụng endpoint này để tạo API key cho tự động hóa, bảng điều khiển nội bộ hoặc tích hợp phía máy chủ.

<Note>
  Tạo personal access token tại [Console → Personal Settings](https://www.cometapi.com/console/personal), sau đó gửi nó dưới dạng giá trị thô của header `Authorization`. Không thêm tiền tố `Bearer`.
</Note>

<Warning>
  Phản hồi tạo chỉ xác nhận thành công. Nó không bao gồm bản ghi key mới hoặc giá trị key. Sau khi tạo, hãy gọi [List API keys](./list-api-keys) để đọc bản ghi key mới nhất.
</Warning>

## Nội dung yêu cầu

| Field                  | Type           | Description                                                                                                                                                                                                                                          |
| ---------------------- | -------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`                 | string         | Tên hiển thị dễ đọc cho key. Phải có tối đa 50 ký tự.                                                                                                                                                                                                |
| `expired_time`         | integer        | Unix timestamp tính bằng giây khi key hết hạn. Dùng `-1` để không hết hạn.                                                                                                                                                                           |
| `remain_quota`         | integer        | Hạn mức khởi đầu theo đơn vị quota nội bộ của CometAPI. Nếu giá trị này đạt `0` và `unlimited_quota` là `false`, các yêu cầu model dùng key này sẽ bị từ chối do đã hết quota.                                                                       |
| `unlimited_quota`      | boolean        | Liệu key có bỏ qua kiểm tra quota còn lại hay không. Chỉ đặt `true` khi key cần tiếp tục hoạt động ngay cả khi `remain_quota` là `0`.                                                                                                                |
| `model_limits_enabled` | boolean        | Liệu có giới hạn key này cho các model cụ thể hay không. Khi là `false`, `model_limits` sẽ bị bỏ qua.                                                                                                                                                |
| `model_limits`         | string         | Các model ID được phép dùng với key này, phân tách bằng dấu phẩy, khi `model_limits_enabled` là `true`. Dùng các model ID được trả về bởi `/v1/models`; dùng chuỗi rỗng nếu không giới hạn model.                                                    |
| `allow_ips`            | string or null | Danh sách IP cho phép tùy chọn. Cung cấp một chuỗi JSON với các mục được phân tách bằng ký tự xuống dòng (`\n`). Mỗi mục có thể là một địa chỉ IPv4 đơn lẻ, địa chỉ IPv6 đơn lẻ, IPv4 CIDR hoặc IPv6 CIDR. Dùng `null` hoặc `""` để tắt giới hạn IP. |
| `group`                | string         | Giới hạn nhóm tài khoản tùy chọn. Dùng chuỗi rỗng nếu không chỉ định nhóm cụ thể. Giá trị không rỗng phải khả dụng cho tài khoản, nếu không API sẽ trả về `success: false`.                                                                          |
| `cross_group_retry`    | boolean        | Liệu cơ chế thử lại liên nhóm có được bật để định tuyến nhóm tự động hay không. Điều này chỉ có ý nghĩa khi key dùng một nhóm được định tuyến tự động.                                                                                               |

## Định dạng danh sách cho phép

Để cho phép nhiều IP hoặc dải CIDR, hãy gửi chúng dưới dạng một chuỗi JSON với `\n` giữa các mục:

```json theme={null}
{
  "allow_ips": "198.51.100.10\n203.0.113.0/24\n2001:db8::/32"
}
```

Ví dụ này cho phép một địa chỉ IPv4, một dải IPv4 CIDR và một dải IPv6 CIDR.


## OpenAPI

````yaml api/openapi/api-keys/create-api-key.openapi.json POST /api/token/
openapi: 3.1.0
info:
  title: Create API Key
  version: 1.0.0
servers:
  - url: https://api.cometapi.com
security:
  - accessTokenAuth: []
paths:
  /api/token/:
    post:
      summary: Create a new API key
      description: >-
        Create an API key for the authenticated account. The response confirms
        success but does not include the new key record or key value; call the
        list endpoint after creation to read the record.
      operationId: createApiKey
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateApiKeyRequest'
            examples:
              default:
                summary: Create an API key
                value:
                  name: production
                  expired_time: -1
                  remain_quota: 100000
                  unlimited_quota: false
                  model_limits_enabled: false
                  model_limits: ''
                  allow_ips: null
                  group: ''
                  cross_group_retry: false
              with_ip_allowlist:
                summary: Configure an IP allowlist
                description: >-
                  Use one JSON string and separate multiple IP or CIDR entries
                  with `\n`.
                value:
                  name: production
                  expired_time: -1
                  remain_quota: 100000
                  unlimited_quota: false
                  model_limits_enabled: false
                  model_limits: ''
                  allow_ips: |-
                    198.51.100.10
                    203.0.113.0/24
                    2001:db8::/32
                  group: ''
                  cross_group_retry: false
      responses:
        '200':
          description: Create result.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ResultEnvelope'
              examples:
                success:
                  summary: Created
                  value:
                    success: true
                    message: ''
                name_too_long:
                  summary: Name too long
                  value:
                    success: false
                    message: token name is too long
      x-codeSamples:
        - lang: curl
          label: cURL
          source: |-
            curl https://api.cometapi.com/api/token/ \
              -H "Authorization: your-access-token" \
              -H "Content-Type: application/json" \
              -d '{
                "name": "production",
                "expired_time": -1,
                "remain_quota": 100000,
                "unlimited_quota": false,
                "model_limits_enabled": false,
                "model_limits": "",
                "allow_ips": null,
                "group": "",
                "cross_group_retry": false
              }'
        - lang: curl
          label: cURL with IP allowlist
          source: |-
            curl https://api.cometapi.com/api/token/ \
              -H "Authorization: your-access-token" \
              -H "Content-Type: application/json" \
              -d '{
              "name": "production",
              "expired_time": -1,
              "remain_quota": 100000,
              "unlimited_quota": false,
              "model_limits_enabled": false,
              "model_limits": "",
              "allow_ips": "198.51.100.10\n203.0.113.0/24\n2001:db8::/32",
              "group": "",
              "cross_group_retry": false
            }'
components:
  schemas:
    CreateApiKeyRequest:
      type: object
      properties:
        name:
          type: string
          maxLength: 50
          description: >-
            User-readable display name for the API key. The backend accepts up
            to 50 Unicode characters; longer names return `success: false` with
            `token name is too long`.
          example: production
        expired_time:
          type: integer
          description: >-
            Unix timestamp in seconds when the key expires. Use `-1` for no
            expiration. A past timestamp blocks model requests with this key.
          example: -1
        remain_quota:
          type: integer
          description: >-
            Starting quota for the new key in CometAPI internal quota units. If
            this reaches `0` while `unlimited_quota` is `false`, model requests
            with this key are rejected as quota exhausted.
          example: 100000
        unlimited_quota:
          type: boolean
          description: >-
            Whether the key bypasses remaining-quota checks. Set `true` only
            when the key should keep working even if `remain_quota` is `0`.
          example: false
        model_limits_enabled:
          type: boolean
          description: >-
            Whether to restrict this key to specific models. When `true`, only
            model IDs listed in `model_limits` are allowed. When `false`,
            `model_limits` is ignored.
          example: false
        model_limits:
          type: string
          description: >-
            Comma-separated model IDs allowed by this key when
            `model_limits_enabled` is `true`. Use model IDs returned by
            `/v1/models`, for example `<model-id-1>,<model-id-2>`. Use an empty
            string for no model restriction.
          example: ''
        allow_ips:
          type:
            - string
            - 'null'
          description: >-
            Optional IP allowlist. Provide one JSON string with entries
            separated by newline characters (`\n`). Each entry can be a single
            IPv4 address, single IPv6 address, IPv4 CIDR, or IPv6 CIDR. Example
            for three allowlist entries:
            `198.51.100.10\n203.0.113.0/24\n2001:db8::/32`. CometAPI compares
            the model request client IP to this list. Use `null` or `""` to
            disable IP restrictions.
          example: |-
            198.51.100.10
            203.0.113.0/24
            2001:db8::/32
        group:
          type: string
          description: >-
            Optional account group restriction. Use an empty string for no
            explicit group restriction. Non-empty values must be available to
            the account, or the API returns `success: false` with a `no access
            to group` message.
          example: ''
        cross_group_retry:
          type: boolean
          description: >-
            Whether cross-group retry is enabled for automatic group routing.
            This is only meaningful when the key uses an auto-routed group such
            as `auto`.
          example: false
      additionalProperties: false
    ResultEnvelope:
      type: object
      required:
        - success
        - message
      properties:
        success:
          type: boolean
          description: Whether the create operation succeeded.
          example: true
        message:
          type: string
          description: >-
            Backend status message. The value is usually an empty string on
            success.
          example: ''
  securitySchemes:
    accessTokenAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Personal access token copied from CometAPI Console > Personal Settings.
        Send the raw token value; do not prefix it with `Bearer`.

````