# Organization API: Customer Portal: Keys

> The 3 Organization API operations for keys.

Source: https://www.coritan.com/docs/api/reference/organizations/customer-portal/object-storage-keys/

Part of [Customer Portal](/docs/api/reference/organizations/customer-portal/).

## Operations

| Method | Path | Summary |
| --- | --- | --- |
| GET | [`/api/v1/orgs/{org_slug}/portal/object-storage/{service_id}/keys`](#op-get-api-v1-orgs-org-slug-portal-object-storage-service-id-keys) | The service's access keys |
| POST | [`/api/v1/orgs/{org_slug}/portal/object-storage/{service_id}/keys`](#op-post-api-v1-orgs-org-slug-portal-object-storage-service-id-keys) | Issue an access key for S3 clients |
| DELETE | [`/api/v1/orgs/{org_slug}/portal/object-storage/{service_id}/keys/{key_id}`](#op-delete-api-v1-orgs-org-slug-portal-object-storage-service-id-keys-key-id) | Revoke an access key |

### The service's access keys {#op-get-api-v1-orgs-org-slug-portal-object-storage-service-id-keys}

`GET /api/v1/orgs/{org_slug}/portal/object-storage/{service_id}/keys`

The service's access keys. The secret of a key is never shown again after it was issued.

#### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `service_id` | path | integer | yes | The Object Storage service's ID, from the service list |
| `org_slug` | path | string | yes |  |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

Fields of a `200` response:

| Field | Type |
| --- | --- |
| `items` | array of KeyOut |
| `items[].id` | integer |
| `items[].access_key_id` | string |
| `items[].label` | string |
| `items[].bucket_id` | integer or null |
| `items[].bucket_name` | string or null |
| `items[].scope` | string, one of `bucket`, `all` |
| `items[].mode` | string, one of `read`, `read_write` |
| `items[].actions` | array of string |
| `items[].is_active` | boolean |
| `items[].last_used_at` | string or null |
| `items[].created_at` | string or null |
| `total` | integer |

### Issue an access key for S3 clients {#op-post-api-v1-orgs-org-slug-portal-object-storage-service-id-keys}

`POST /api/v1/orgs/{org_slug}/portal/object-storage/{service_id}/keys`

Issue an access key for S3 clients. The secret is in this answer and nowhere else after.

``mode`` is ``read`` (read and list) or ``read_write``. With ``bucket_id`` the
key opens that one bucket. Without it, the key opens every bucket of the
service, the ones made later included. A key never creates or deletes
buckets. ``label`` is 1 to 64 characters and unique in the service. A new key
works within a couple of minutes. Answers 409 for a label already in use and
when the service is not active, and 404 for a bucket that is not the
customer's.

#### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `service_id` | path | integer | yes | The Object Storage service's ID, from the service list |
| `org_slug` | path | string | yes |  |

#### Request body

`application/json` (required)

| Field | Type | Required |
| --- | --- | --- |
| `label` | string | yes |
| `bucket_id` | integer or null | no |
| `mode` | string, one of `read`, `read_write` | no |

#### Responses

| Status | Meaning |
| --- | --- |
| `201` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

Fields of a `201` response:

| Field | Type |
| --- | --- |
| `id` | integer |
| `access_key_id` | string |
| `label` | string |
| `bucket_id` | integer or null |
| `bucket_name` | string or null |
| `scope` | string, one of `bucket`, `all` |
| `mode` | string, one of `read`, `read_write` |
| `actions` | array of string |
| `is_active` | boolean |
| `last_used_at` | string or null |
| `created_at` | string or null |
| `secret_key` | string |
| `endpoint` | string or null |
| `region` | string or null |
| `activation_note` | string |

### Revoke an access key {#op-delete-api-v1-orgs-org-slug-portal-object-storage-service-id-keys-key-id}

`DELETE /api/v1/orgs/{org_slug}/portal/object-storage/{service_id}/keys/{key_id}`

Revoke an access key. It stops working within a couple of minutes, and a revoked key cannot be restored.

Answers 404 for a key that is not in this customer's service.

#### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `service_id` | path | integer | yes | The Object Storage service's ID, from the service list |
| `key_id` | path | integer | yes | The access key's ID, from the service's key list |
| `org_slug` | path | string | yes |  |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

Fields of a `200` response:

| Field | Type |
| --- | --- |
| `ok` | boolean |
| `access_key_id` | string |
