> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nexenergie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Create and Manage Nexenergie API Keys for Secure API Access

> Generate long-lived API keys from the Nexenergie dashboard to authenticate programmatic requests without re-issuing tokens every 24 hours.

API keys are for server-to-server access. Only tenant **admins** can create or revoke them. The raw secret is shown **once** on create.

## Create a key

```bash theme={null}
curl -sS https://<host>/api/v1/auth/api-keys \
  -H "Authorization: Bearer <access_jwt>" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "oms-integration",
    "scopes": ["role:viewer", "markets:read", "forecasts:read"],
    "expires_in_days": 90
  }'
```

Store `api_key` from the response. Later list and delete calls only show `key_prefix`.

<AccordionGroup>
  <Accordion title="name">
    1–100 characters.
  </Accordion>

  <Accordion title="scopes">
    Defaults to `["role:viewer"]`.
  </Accordion>

  <Accordion title="expires_in_days">
    Optional, 1–365. Omit for no expiry.
  </Accordion>
</AccordionGroup>

## Call the API

```bash theme={null}
curl -sS "https://<host>/api/v1/forecasts/latest?market_id=omie_es&product=da" \
  -H "Authorization: Bearer nex_..."
```

## Scopes

<AccordionGroup>
  <Accordion title="role:viewer, role:trader, role:manager, role:admin">
    Maps the key to a tenant role.
  </Accordion>

  <Accordion title="markets:read">
    Required if the key lists any fine-grained scopes and you call `/markets`.
  </Accordion>

  <Accordion title="forecasts:read">
    Required if the key lists any fine-grained scopes and you call `/forecasts`.
  </Accordion>
</AccordionGroup>

<Warning>
  If you set `markets:read` but omit `forecasts:read`, forecast endpoints return 403. Either use only a `role:*` scope, or include every fine-grained scope you need.
</Warning>

## Revoke

```bash theme={null}
curl -sS -X DELETE https://<host>/api/v1/auth/api-keys/<api_key_id> \
  -H "Authorization: Bearer <access_jwt>"
```
