> ## Documentation Index
> Fetch the complete documentation index at: https://docs.earthity.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Mint a sandbox API key

> Mints an anonymous API key with no account, no session and no credential of any kind - the first step of the quickstart. The key drives the sandbox (`https://outpost.earthity.com/api/sandbox`) for 24 hours and then stops authenticating. It belongs to no organization and owns no docks, so production accepts it as a valid credential but answers every dock with `404 not_found`, as if the dock did not exist; that is the signal to sign in and mint an org key from the dashboard Integration page. An anonymous key cannot be upgraded into an org key later. The secret is in the response once and is never retrievable again. `GET` on this path does not mint - it answers `400` - so a crawler or link preview can never create a key. Minting is limited to 10 keys per IP per hour, under a shared hourly allowance for all anonymous keys.

## `POST /api/sandbox/keys`

* **Production:** `POST https://outpost.earthity.com/api/sandbox/keys`
* **Gate:** `public`
* **Read-only:** `false`
* **Destructive:** `false`
* **Idempotent:** `false`

## Request body

| Property | Type | Required | Constraints | Description |
| - | - | - | - | - |
| `name` | `string` | no | maxLength: 80 | A label for your own reference, e.g. `my laptop`. Trimmed. A missing, empty or longer-than-80-character value is not an error: the key is labelled `Sandbox key` instead. |

## Responses

### `201` - Key minted.

| Header | Description |
| - | - |
| `Cache-Control` | `no-store` - the body is a credential. |

| Property | Type | Required | Constraints | Description |
| - | - | - | - | - |
| `secret` | `string` | yes | - | The API key, e.g. `opk_...`. Send it as `Authorization: Bearer <secret>`. Shown once: there is no reveal for an anonymous key, so store it now or mint another. |
| `expiresAt` | `string` | yes | format: date-time | When the key stops authenticating: 24 hours after it was minted. |
| `scope` | `string` | yes | enum: sandbox | Always `sandbox`. The key belongs to no organization, so it owns no docks: production authenticates it but answers every dock with `404 not_found`. |
| `note` | `string` | yes | - | A human-readable reminder of the limits above. Informational; do not parse it. |

### `429` - Too many keys: more than 10 from this IP in the last hour, or the hourly allowance shared by every anonymous mint is used up. Wait for `Retry-After` seconds. A key you already hold keeps working; an org key from the dashboard is never subject to this limit.

Body: `application/problem+json` - see [Problem anatomy](/errors#problem-anatomy).

### `503` - The rate limiter is unreachable, so the endpoint refuses rather than mint unmetered. It shares the sandbox's limiter, which reports this as `command_unavailable` even though no command is involved. Retry after `Retry-After` seconds.

Body: `application/problem+json` - see [Problem anatomy](/errors#problem-anatomy).

## Errors

* [rate\_limited](/errors#rate_limited)
* [command\_unavailable](/errors#command_unavailable)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.