> ## Documentation Index
> Fetch the complete documentation index at: https://deepline.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Clickhouse Openapi Key Create: Inputs, Cost & CLI Example

> Create key. Clickhouse Clickhouse Openapi Key Create docs include request fields, response shape, pricing notes, and Deepline CLI examples.

## Run in Enrichment Spreadsheet

<Info>
  Use this function as a column step in `deepline enrich`.
</Info>

```bash theme={null}
deepline enrich --input leads.csv --output leads.enriched.csv --with 'result=clickhouse_openapi_key_create:{"organizationId":"{{organizationId}}"}' --json
```

<Tip>
  Map payload values to spreadsheet columns with `{{column_name}}` placeholders.
</Tip>

## Input Schema

| Name                      | Type                      | Required | Default | Description                                                                                                |
| ------------------------- | ------------------------- | -------- | ------- | ---------------------------------------------------------------------------------------------------------- |
| `payload.organizationId`  | `string`                  | Yes      |         | ID of the organization that will own the key.                                                              |
| `payload.name`            | `string`                  | No       |         | Name of the key.                                                                                           |
| `payload.expireAt`        | `string`                  | No       |         | Timestamp the key expires. If not present, `null` or is empty the key never expires. ISO-8601.             |
| `payload.state`           | `"enabled" \| "disabled"` | No       |         | Initial state of the key: 'enabled', 'disabled'. If not provided the new key will be 'enabled'.            |
| `payload.hashData`        | `object`                  | No       |         |                                                                                                            |
| `payload.roles`           | `array`                   | No       |         | DEPRECATED. Use `assignedRoleIds` instead. List of roles assigned to the key. Contains at least 1 element. |
| `payload.assignedRoleIds` | `array`                   | No       |         | Array of role UUIDs to assign to the API key                                                               |
| `payload.ipAccessList`    | `array`                   | No       |         | List of IP addresses allowed to access the API using this key                                              |

### Allowed values

| Field           | Allowed values        |
| --------------- | --------------------- |
| `payload.state` | `enabled`, `disabled` |

<details>
  <summary>Show raw input schema</summary>

  ### Input JSON Schema

  ```json theme={null}
  {
    "type": "object",
    "description": "Creates new API key.",
    "properties": {
      "organizationId": {
        "type": "string",
        "description": "ID of the organization that will own the key.",
        "format": "uuid"
      },
      "name": {
        "type": "string",
        "description": "Name of the key."
      },
      "expireAt": {
        "type": [
          "string",
          "null"
        ],
        "description": "Timestamp the key expires. If not present, `null` or is empty the key never expires. ISO-8601.",
        "format": "date-time"
      },
      "state": {
        "type": "string",
        "description": "Initial state of the key: 'enabled', 'disabled'. If not provided the new key will be 'enabled'.",
        "enum": [
          "enabled",
          "disabled"
        ]
      },
      "hashData": {
        "properties": {
          "keyIdHash": {
            "type": "string",
            "description": "Hash of the key ID."
          },
          "keyIdSuffix": {
            "type": "string",
            "description": "Last 4 digits of the key ID. Algorithm: echo -n \"yourpassword\" | sha256sum | tr -d '-' | xxd -r -p | base64"
          },
          "keySecretHash": {
            "type": "string",
            "description": "Hash of the key secret. Algorithm: echo -n \"yourpassword\" | sha256sum | tr -d '-' | xxd -r -p | base64"
          }
        },
        "additionalProperties": false
      },
      "roles": {
        "type": "array",
        "description": "DEPRECATED. Use `assignedRoleIds` instead. List of roles assigned to the key. Contains at least 1 element.",
        "items": {
          "type": "string",
          "enum": [
            "admin",
            "developer",
            "query_endpoints"
          ]
        }
      },
      "assignedRoleIds": {
        "type": "array",
        "description": "Array of role UUIDs to assign to the API key",
        "items": {
          "type": "string",
          "format": "uuid"
        }
      },
      "ipAccessList": {
        "type": "array",
        "description": "List of IP addresses allowed to access the API using this key",
        "items": {
          "properties": {
            "source": {
              "type": "string",
              "description": "IP or CIDR"
            },
            "description": {
              "type": "string",
              "description": "Optional description of IPv4 address or IPv4 CIDR to allow access from"
            }
          },
          "additionalProperties": false
        }
      }
    },
    "required": [
      "organizationId"
    ],
    "additionalProperties": false
  }
  ```
</details>

## Output Schema

| Name          | Type     | Required | Default | Description                                    |
| ------------- | -------- | -------- | ------- | ---------------------------------------------- |
| `result.data` | `object` | Yes      |         | Provider response payload.                     |
| `result.meta` | `object` | No       |         | Additional response metadata (status, paging). |

<details>
  <summary>Show raw output schema</summary>

  ### Output JSON Schema

  ```json theme={null}
  {
    "type": "object",
    "description": "Standard tool result payload.",
    "properties": {
      "data": {
        "type": "object",
        "description": "Provider response payload.",
        "properties": {
          "status": {
            "type": "number",
            "description": "HTTP status code."
          },
          "requestId": {
            "type": "string",
            "description": "Unique id assigned to every request. UUIDv4",
            "format": "uuid"
          },
          "result": {
            "properties": {
              "key": {
                "properties": {
                  "id": {
                    "type": "string",
                    "description": "Unique API key ID.",
                    "format": "uuid"
                  },
                  "name": {
                    "type": "string",
                    "description": "Name of the key"
                  },
                  "state": {
                    "type": "string",
                    "description": "State of the key: 'enabled', 'disabled'.",
                    "enum": [
                      "enabled",
                      "disabled"
                    ]
                  },
                  "roles": {
                    "type": "array",
                    "description": "DEPRECATED. Use `assignedRoles` instead. List of roles assigned to the key. For organizations that have migrated to custom roles, this field is frozen at the pre-migration value and does not reflect current role assignments.",
                    "items": {
                      "type": "string",
                      "enum": [
                        "admin",
                        "developer",
                        "query_endpoints"
                      ]
                    }
                  },
                  "assignedRoles": {
                    "type": "array",
                    "description": "Custom roles and System roles assigned to this API key",
                    "items": {
                      "properties": {
                        "roleId": {
                          "type": "string",
                          "description": "Unique identifier of the role",
                          "format": "uuid"
                        },
                        "roleName": {
                          "type": "string",
                          "description": "Human-readable name of the role"
                        },
                        "roleType": {
                          "type": "string",
                          "description": "Type of role: system (predefined) or custom (organization-defined)",
                          "enum": [
                            "system",
                            "custom"
                          ]
                        }
                      },
                      "additionalProperties": false
                    }
                  },
                  "keySuffix": {
                    "type": "string",
                    "description": "Last 4 letters of the key."
                  },
                  "createdAt": {
                    "type": "string",
                    "description": "Timestamp the key was created. ISO-8601.",
                    "format": "date-time"
                  },
                  "expireAt": {
                    "type": [
                      "string",
                      "null"
                    ],
                    "description": "Timestamp the key expires. If not present, `null` or is empty the key never expires. ISO-8601.",
                    "format": "date-time"
                  },
                  "usedAt": {
                    "type": "string",
                    "description": "Timestamp the key was used last time, with one-minute precision. If not present the key was never used. ISO-8601.",
                    "format": "date-time"
                  },
                  "ipAccessList": {
                    "type": "array",
                    "description": "List of IP addresses allowed to access the API using this key",
                    "items": {
                      "properties": {
                        "source": {
                          "type": "string",
                          "description": "IP or CIDR"
                        },
                        "description": {
                          "type": "string",
                          "description": "Optional description of IPv4 address or IPv4 CIDR to allow access from"
                        }
                      },
                      "additionalProperties": false
                    }
                  }
                },
                "additionalProperties": false
              },
              "keyId": {
                "type": "string",
                "description": "Generated key ID. Provided only if there was no 'hashData' in the request."
              },
              "keySecret": {
                "type": "string",
                "description": "Generated key secret. Provided only if there was no 'hashData' in the request."
              }
            },
            "additionalProperties": false
          }
        },
        "additionalProperties": false
      },
      "meta": {
        "type": "object",
        "description": "Additional response metadata (status, paging).",
        "additionalProperties": true
      }
    },
    "required": [
      "data"
    ],
    "additionalProperties": false
  }
  ```
</details>

## Advanced: Direct CLI

<Info>
  Use direct execution for single payload debugging.
</Info>

```bash theme={null}
deepline tools execute clickhouse_openapi_key_create --payload '{
  "organizationId": "string"
}' --json
```

### CLI flags

| Flag                        | Description                                         |
| --------------------------- | --------------------------------------------------- |
| `--json`                    | Print machine-readable output.                      |
| `--wait`                    | Wait for terminal provider status when supported.   |
| `--debug`                   | Enable wait mode with additional status/log output. |
| `--wait-timeout SECONDS`    | Max seconds to wait in wait mode.                   |
| `--poll-interval SECONDS`   | Polling interval in seconds during wait mode.       |
| `--timeout SECONDS`         | Request timeout in seconds.                         |
| `--connect-timeout SECONDS` | Connection timeout in seconds.                      |

## Cost

* Pricing model: `fixed` (per call).
* Estimated Deepline credits: `0` per pricing unit.
* Provider-native pricing may still exist outside Deepline credit billing.
* Billing mode: `no_bill`.
