> ## Documentation Index
> Fetch the complete documentation index at: https://docs.honeyhive.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Plane Api Keys

> Create fine-grained data plane API keys for a project from a provisioning flow, using an organization-rooted key that is permitted to create keys.

## Schema introspection

Every command below with arguments supports two read-only flags for tooling and AI agents:

* `--show-file-schema`: print the JSON Schema for the full request object (the format `--filename` accepts).
* `--show-argument-schema <flag-name>`: print the JSON Schema for one argument's value. Pass the kebab flag name **without** the leading `--` (e.g. `project-id`, not `--project-id`).

Both write pure JSON to stdout and never call the API. They cannot be combined with any other command-specific flag.

## `create`

Create a data plane API key

Create a fine-grained data plane API key rooted at a project. The caller's key must carry `project.fine_grained_api_key_dp.post` for the project. Only an organization-rooted key created in the organization's **Settings → API Keys**, on the **Data Plane** tab, can carry it, and a key created through this operation never can, so a provisioned key cannot create keys. The permissions requested are limited to the organization's data plane key policy, and `expires_at` to the system's maximum lifetime. The project must already exist on this data plane: a project created on the control plane reaches it asynchronously, and the operation answers 404 until it does. `key_value` is returned once and cannot be retrieved again.

### Usage

```sh theme={null}
honeyhive data-plane-api-keys create [options]
```

### Options

| Flag | Type | Required | Description |
| - | - | - | - |
| `--expires-at` | string | yes | When the key expires, as an ISO 8601 timestamp. It must be in the future and within the maximum key lifetime; a later value is refused with the limit named. |
| `--name` | string | yes | A name for the key, shown in the key list. |
| `--permissions` | json | yes | The permissions the key carries, such as `project.chart.get`. Each must be one the key's root scope can carry and one the organization's data plane key policy allows; the key creation screen under the project's Settings → API Keys lists them. |
| `--project-id` | string | yes | The unique identifier of the project the key is rooted at |
| `--description` | string | no | What the key is for. |

Also supports `--show-file-schema`, `--show-argument-schema <flag-name>`, and `--filename`. See [Schema introspection](#schema-introspection) for details.


## Related topics

- [API Keys](/v2/workspace/api-keys.md)
- [Data Plane Api Keys Methods](/v2/sdk-reference/typescript/ref/data-plane-api-keys/index.md)
- [CreateDataPlaneApiKeyRequest](/v2/sdk-reference/typescript/ref/data-plane-api-keys/CreateDataPlaneApiKeyRequest.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.