{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/algolia/main/json-schema/algolia-api-key-schema.json", "title": "apiKey", "description": "API key object.", "x-generated": "2026-09-23", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/algolia-search-api-openapi.yml#/components/schemas/apiKey", "type": "object", "additionalProperties": false, "properties": { "acl": { "type": "array", "description": "Permissions that determine the type of API requests this key can make.\nThe required ACL is listed in each endpoint's reference.\nFor more information, see [access control list](https://www.algolia.com/doc/guides/security/api-keys/#access-control-list-acl).\n", "default": [], "items": { "$ref": "#/$defs/acl" } }, "description": { "type": "string", "description": "Description of an API key to help you identify this API key.", "default": "" }, "indexes": { "type": "array", "description": "Index names or patterns that this API key can access.\nBy default, an API key can access all indices in the same application.\n\nYou can use leading and trailing wildcard characters (`*`):\n\n- `dev_*` matches all indices starting with \"dev_\"\n- `*_dev` matches all indices ending with \"_dev\"\n- `*_products_*` matches all indices containing \"_products_\".\n", "default": [], "items": { "type": "string" } }, "maxHitsPerQuery": { "type": "integer", "description": "Maximum number of results this API key can retrieve in one query.\nBy default, there's no limit.\n", "default": 0 }, "maxQueriesPerIPPerHour": { "type": "integer", "description": "Maximum number of API requests allowed per IP address or [user token](https://www.algolia.com/doc/guides/sending-events/concepts/usertoken) per hour.\n\nIf this limit is reached, the API returns an error with status code `429`.\nBy default, there's no limit.\n", "default": 0 }, "queryParameters": { "type": "string", "description": "Query parameters to add when making API requests with this API key.\n\nTo restrict this API key to specific IP addresses, add the `restrictSources` parameter.\nYou can only add a single source, but you can provide a range of IP addresses.\n\nCreating an API key fails if the request is made from an IP address outside the restricted range.\n", "default": "" }, "referers": { "type": "array", "description": "Allowed HTTP referrers for this API key.\n\nBy default, all referrers are allowed.\nYou can use leading and trailing wildcard characters (`*`):\n\n- `https://algolia.com/*` allows all referrers starting with \"https://algolia.com/\"\n- `*.algolia.com` allows all referrers ending with \".algolia.com\"\n- `*algolia.com*` allows all referrers in the domain \"algolia.com\".\n\nLike all HTTP headers, referrers can be spoofed. Don't rely on them to secure your data.\nFor more information, see [HTTP referrer restrictions](https://www.algolia.com/doc/guides/security/security-best-practices/#http-referrers-restrictions).\n", "default": [], "items": { "type": "string" } }, "validity": { "type": "integer", "description": "Duration (in seconds) after which the API key expires.\nBy default, API keys don't expire.\n", "default": 0 } }, "required": [ "acl" ], "$defs": { "acl": { "description": "Access control list permissions.", "type": "string", "enum": [ "addObject", "analytics", "browse", "deleteObject", "deleteIndex", "editSettings", "inference", "listIndexes", "logs", "personalization", "recommendation", "search", "seeUnretrievableAttributes", "settings", "usage", "nluWriteProject", "nluReadProject", "nluWriteEntity", "nluReadEntity", "nluWriteIntent", "nluReadIntent", "nluPrediction", "nluReadAnswers" ] } } }