
Create an xAI API key via the Management API
Mint a new inference API key for a team over HTTP when provisioning, CI secrets, or least-privilege runbooks need a named key with explicit endpoint and model ACLs, optional rate limits, and a one-time secret you store immediately. Official Accounts and Authorization documents POST /auth/teams/{teamId}/api-keys on https://management-api.x.ai, authorized with a management key. The Management API guide shows a create example with wildcards, qps, qpm, and an optional tpm limit. The response returns the full secret once in apiKey, plus apiKeyId, redactedApiKey, aclStrings, and metadata you need for later update, rotate, or delete. Create the management key first with Create a management key in the xAI Console if you do not already have one.
What you need
A management key that can create API keys for the team, the team id from Console Settings → Team, ACL strings from the models and endpoints list routes, and a secrets store ready to capture apiKey before the terminal scroll leaves the screen. Neighboring key jobs include List team models via the xAI Management API, List endpoint ACLs via the xAI Management API, and Check API key propagation via the xAI Management API. More API jobs live on the API hub.
Create the key
- Export the management key and team id outside of source control. Prefer ACL values you already pulled from the models and endpoints GETs rather than inventing strings:
export XAI_MANAGEMENT_KEY="your_management_key"
export XAI_TEAM_ID="your_team_id"
- Create an API key. The guide example grants all models and endpoints, limits to five queries per second and one hundred per minute, and leaves token-per-minute unset:
curl "https://management-api.x.ai/auth/teams/${XAI_TEAM_ID}/api-keys" \
-X POST \
-H "Authorization: Bearer ${XAI_MANAGEMENT_KEY}" \
-H "Content-Type: application/json" \
-d '{
"name": "My API key",
"acls": ["api-key:model:*", "api-key:endpoint:*"],
"qps": 5,
"qpm": 100,
"tpm": null
}'
Narrow the
aclsarray when the key should not be a wildcard. Combine strings such asapi-key:endpoint:chatwith specificapi-key:model:<name>values from List team models via the xAI Management API. By default a new key has no access until you grant both endpoint and model ACLs. Optional body fields also includeexpireTimewhen the key must stop working after a deadline, andtpmas an integer string when you need a tokens-per-minute cap; the guide notes the limiter engages when the limit is strictly exceeded and in-flight requests continue.Store
apiKeyimmediately in your secret manager. Later GETs only returnredactedApiKey. KeepapiKeyIdfor Update an xAI API key via the Management API, rotate, delete, and Check API key propagation via the xAI Management API before you route production traffic to the new secret.
Keep every call on https://management-api.x.ai. An inference API key against https://api.x.ai will not create sibling keys.
Hand off after create
Wire create into the same runbook that polls propagation and then swaps clients onto the new secret. When you only need a Console-minted key without automation, use Console API Keys and still record apiKeyId for later Management updates. Pair with Manage API keys with the xAI Management API for the broader list, rotate, and delete sequence around this single create job.
Pitfalls
Skipping the acls array or leaving it empty yields a key that authenticates nowhere useful. Losing the one-time apiKey field forces a rotate or a brand-new create because list responses never re-expose the full secret. Shipping traffic before propagation reports true on required clusters produces intermittent auth failures. Calling create with an inference key or against https://api.x.ai never hits this Management route.