Headscale unofficial
POST/api/v1/preauthkey

Create a pre-auth key

Creates a pre-auth key for a user. Configure the key with fields such as user, expiration, reusable, ephemeral, and aclTags; user is a uint64-formatted string and expiration is a date-time.

  • IdempotentThe SDK sends Idempotency-Key, so a retried request is only applied once.

5 body fields

Pre-auth key configuration; all fields are optional.

aclTagsarray<string>optional
ACL tags to associate with the key, provided as an array of strings.
ephemeralbooleanoptional
Whether nodes registered with this key are ephemeral.
expirationstringoptional
The key's expiration date and time in date-time format.
reusablebooleanoptional
Whether the key can be used more than once.
userstringoptional
The user's identifier as a uint64-formatted string.

2 status codes
200Returns an object containing the created `preAuthKey`, including its user, identifier, key value, settings, usage state, expiration, creation time, and ACL tags.
preAuthKeyobjectrequired
defaultReturned when the request fails; includes a problem details object with information about the error.
detailstringoptional
A human-readable explanation specific to this occurrence of the problem.
errorsarray<object>optional
Optional list of individual error details
instancestringoptional
A URI reference that identifies the specific occurrence of the problem.
statusintegeroptional
HTTP status code
titlestringoptional
A short, human-readable summary of the problem type. This value should not change between occurrences of the error.
typestringoptional
A URI reference to human-readable documentation for the error.
Default:about:blank

Error handling

The request body is required, but no body fields are marked as required. When supplied, user must be a uint64-formatted string, expiration must use date-time format, and aclTags must be an array of strings.