curl --request POST \
--url https://app.auditynow.com/api/user/api-keys \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"label": "Claude Desktop, MacBook Pro",
"scopes": [
"read",
"write"
]
}
'import requests
url = "https://app.auditynow.com/api/user/api-keys"
payload = {
"label": "Claude Desktop, MacBook Pro",
"scopes": ["read", "write"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({label: 'Claude Desktop, MacBook Pro', scopes: ['read', 'write']})
};
fetch('https://app.auditynow.com/api/user/api-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.auditynow.com/api/user/api-keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'label' => 'Claude Desktop, MacBook Pro',
'scopes' => [
'read',
'write'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.auditynow.com/api/user/api-keys"
payload := strings.NewReader("{\n \"label\": \"Claude Desktop, MacBook Pro\",\n \"scopes\": [\n \"read\",\n \"write\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.auditynow.com/api/user/api-keys")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"label\": \"Claude Desktop, MacBook Pro\",\n \"scopes\": [\n \"read\",\n \"write\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.auditynow.com/api/user/api-keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"label\": \"Claude Desktop, MacBook Pro\",\n \"scopes\": [\n \"read\",\n \"write\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"label": "<string>",
"tokenPrefix": "<string>",
"scopes": [
"read"
],
"createdAt": "2023-11-07T05:31:56Z",
"plaintext": "<string>",
"expiresAt": "2023-11-07T05:31:56Z",
"lastUsedAt": "2023-11-07T05:31:56Z"
}{
"error": "<string>",
"details": "<string>"
}{
"error": "Unauthorized"
}{
"error": "<string>",
"code": "<string>"
}{
"error": "<string>",
"details": "<string>"
}{
"error": "<string>",
"details": "<string>"
}Create a new Personal Access Token (browser session only)
Creates a new PAT for the authenticated user. The plaintext token is returned ONLY in this response, it cannot be retrieved later. Store it immediately.
Browser session required. PATs cannot create other PATs.
Constraints: maximum of 10 active tokens per user. Creating an 11th returns 409.
Valid scopes: read, write. Tokens with no valid scopes return 400.
curl --request POST \
--url https://app.auditynow.com/api/user/api-keys \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"label": "Claude Desktop, MacBook Pro",
"scopes": [
"read",
"write"
]
}
'import requests
url = "https://app.auditynow.com/api/user/api-keys"
payload = {
"label": "Claude Desktop, MacBook Pro",
"scopes": ["read", "write"]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({label: 'Claude Desktop, MacBook Pro', scopes: ['read', 'write']})
};
fetch('https://app.auditynow.com/api/user/api-keys', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.auditynow.com/api/user/api-keys",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'label' => 'Claude Desktop, MacBook Pro',
'scopes' => [
'read',
'write'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.auditynow.com/api/user/api-keys"
payload := strings.NewReader("{\n \"label\": \"Claude Desktop, MacBook Pro\",\n \"scopes\": [\n \"read\",\n \"write\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.auditynow.com/api/user/api-keys")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"label\": \"Claude Desktop, MacBook Pro\",\n \"scopes\": [\n \"read\",\n \"write\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.auditynow.com/api/user/api-keys")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"label\": \"Claude Desktop, MacBook Pro\",\n \"scopes\": [\n \"read\",\n \"write\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"label": "<string>",
"tokenPrefix": "<string>",
"scopes": [
"read"
],
"createdAt": "2023-11-07T05:31:56Z",
"plaintext": "<string>",
"expiresAt": "2023-11-07T05:31:56Z",
"lastUsedAt": "2023-11-07T05:31:56Z"
}{
"error": "<string>",
"details": "<string>"
}{
"error": "Unauthorized"
}{
"error": "<string>",
"code": "<string>"
}{
"error": "<string>",
"details": "<string>"
}{
"error": "<string>",
"details": "<string>"
}Authorizations
A Personal Access Token issued from https://app.auditynow.com/dashboard/settings/api-tokens. Format: aky_<32 random chars>.
Body
Human label for the token (e.g. Claude Desktop, MacBook Pro).
1 - 100Token scopes. Defaults to ["read"] if omitted.
read, write Optional explicit expiry. Server does not enforce a default expiry.
Response
Token created. The plaintext field is returned ONCE, never again.
Safe-to-display metadata for a Personal Access Token. The plaintext token is NEVER returned here, only on creation.
User-supplied label for the token.
First 6 chars of the token (e.g. aky_a1b), for visual identification.
read, write The full PAT (aky_<32 chars>). Returned ONCE at creation, never retrievable again. Store immediately.

